Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.

Antwort
Alt 12.10.2013, 20:30   #1
Wild-Pako
 
Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome - Beitrag

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome



Hallo Leute,

seit gerauemer Zeit habe ich auf jeder Webseite Flash Werbung und Popups im überfluss. Die üblichen Firefox Plugins wie Adblock sind installiert, bringen aber nur bedingt etwas. Es findet keine Umleitung auf andere Webseiten statt, lediglich Werbung wird Massenhaft angezeigt.

Angehängt sind die Log Dateien wie in eurem Info Thread beschrieben.

vielen Dank schonmal vorab für die Hilfe.

Gruß,
Michael

Alt 12.10.2013, 23:11   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome - Standard

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome



Hi,

Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen.


So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________

__________________

Alt 12.10.2013, 23:57   #3
Wild-Pako
 
Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome - Standard

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome



Code:
ATTFilter
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 20:09 on 12/10/2013 (Wild-Pako)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
HKCU:DAEMON Tools Lite -> Removed

Checking for services/drivers...


-=E.O.F=-
         
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2013
Ran by Wild-Pako at 2013-10-12 20:11:02
Running from D:\! - - Transfer - - !
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: avast! Antivirus (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AS: avast! Antivirus (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}

==================== Installed Programs ======================

3DMark Vantage (x32 Version: 1.1.2)
3DMark06 (x32 Version: 1.2.1)
Adobe Flash Player 10 ActiveX (x32 Version: 10.0.32.18)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Reader 9.1 - Deutsch (x32 Version: 9.1.0)
AMD Accelerated Video Transcoding (Version: 13.15.100.30830)
AMD APP SDK Runtime (Version: 10.0.937.2)
AMD Catalyst Control Center (x32 Version: 2013.0830.1944.33589)
AMD Catalyst Install Manager (Version: 8.0.915.0)
AMD Drag and Drop Transcoding (Version: 2.00.0000)
AMD Media Foundation Decoders (Version: 1.0.80830.1925)
avast! Free Antivirus (x32 Version: 8.0.1497.0)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0830.1944.33589)
Catalyst Control Center InstallProxy (x32 Version: 2013.0830.1944.33589)
Catalyst Control Center Localization All (x32 Version: 2013.0830.1944.33589)
CCC Help Chinese Standard (x32 Version: 2013.0830.1943.33589)
CCC Help Chinese Traditional (x32 Version: 2013.0830.1943.33589)
CCC Help Czech (x32 Version: 2013.0830.1943.33589)
CCC Help Danish (x32 Version: 2013.0830.1943.33589)
CCC Help Dutch (x32 Version: 2013.0830.1943.33589)
CCC Help English (x32 Version: 2013.0830.1943.33589)
CCC Help Finnish (x32 Version: 2013.0830.1943.33589)
CCC Help French (x32 Version: 2013.0830.1943.33589)
CCC Help German (x32 Version: 2013.0830.1943.33589)
CCC Help Greek (x32 Version: 2013.0830.1943.33589)
CCC Help Hungarian (x32 Version: 2013.0830.1943.33589)
CCC Help Italian (x32 Version: 2013.0830.1943.33589)
CCC Help Japanese (x32 Version: 2013.0830.1943.33589)
CCC Help Korean (x32 Version: 2013.0830.1943.33589)
CCC Help Norwegian (x32 Version: 2013.0830.1943.33589)
CCC Help Polish (x32 Version: 2013.0830.1943.33589)
CCC Help Portuguese (x32 Version: 2013.0830.1943.33589)
CCC Help Russian (x32 Version: 2013.0830.1943.33589)
CCC Help Spanish (x32 Version: 2013.0830.1943.33589)
CCC Help Swedish (x32 Version: 2013.0830.1943.33589)
CCC Help Thai (x32 Version: 2013.0830.1943.33589)
CCC Help Turkish (x32 Version: 2013.0830.1943.33589)
ccc-utility64 (Version: 2013.0830.1944.33589)
CDBurnerXP (x32 Version: 4.5.2.4291)
Core Temp 1.0 RC5 (Version: 1.0)
CPUID CPU-Z 1.61.3
CrossLoop 2.82 (x32 Version: 2.82)
DAEMON Tools Lite (x32 Version: 4.45.4.0314)
Defraggler (Version: 2.15)
DMUninstaller (x32)
Dropbox (HKCU Version: 2.0.26)
DU Meter (x32 Version: 4.16 Build R3102)
EL3K My ELAS Remote Programmer 2.01.01 (x32 Version: 2.01.01)
Far Cry 3 (x32 Version: 1.05)
FBL Gyro Programmer version 1.15 (x32 Version: 1.15)
Feven 1.5 (x32 Version: 1.28.153.2)
FileZilla Client 3.7.3 (x32 Version: 3.7.3)
FMS
FMS (x32)
Futuremark SystemInfo (x32 Version: 4.17.0)
Google Chrome (x32 Version: 30.0.1599.69)
Grand Theft Auto IV Complete Edition (x32 Version: v1.0.7.0/1.1.2.0)
GTAIII (x32)
HELI-X 4.2 Demo (x32)
IrfanView (remove only) (x32)
Java 7 Update 40 (x32 Version: 7.0.400)
Java Auto Updater (x32 Version: 2.1.9.8)
JDownloader 0.9 (x32 Version: 0.9)
K-Lite Codec Pack 5.3.0 (64-bit) (Version: 5.3.0)
K-Lite Mega Codec Pack 7.8.0 (x32 Version: 7.8.0)
Microsoft .NET Framework 4.5 (Version: 4.5.50709)
Microsoft .NET Framework 4.5 DEU Language Pack (Version: 4.5.50709)
Microsoft Application Compatibility Toolkit 5.6 (x32 Version: 5.6.7324.0)
Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.92.0)
Microsoft Games for Windows Marketplace (x32 Version: 3.5.67.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (x32 Version: 11.0.50727.1)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (x32 Version: 11.0.50727.1)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727)
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727)
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727)
Miranda IM 0.10.17 (x32 Version: 0.10.17)
Mozilla Firefox 24.0 (x86 de) (x32 Version: 24.0)
Mozilla Maintenance Service (x32 Version: 24.0)
Mozilla Thunderbird 24.0 (x86 de) (x32 Version: 24.0)
MPC-HC 1.7.0 (64-bit) (Version: 1.7.0.7858)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
Need for Speed Most Wanted (x32)
NVIDIA Install Application (Version: 2.1002.133.902)
NVIDIA PhysX (x32 Version: 9.12.1031)
OpenAL (x32)
OpenOffice 4.0.0 (x32 Version: 4.00.9702)
PhoenixRC (x32 Version: 3.00.16)
PL-2303 USB-to-Serial (x32 Version: 1.2.10)
PlanetSide 2 PSG (HKCU Version: 1.0.3.183)
QuickTime (x32 Version: 7.73.80.64)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.5874)
Shutdown Timer (x32 Version: 3.3.4)
SKIP-BO Castaway Caper(TM) (HKCU Version: 1.0.0)
SKIP-BO Castaway Caper(TM) (x32 Version: 1.0.0)
Spybot - Search & Destroy (x32 Version: 2.1.21)
Steamless Mafia II Pack (x32 Version: 1.0)
TeamViewer 8 (x32 Version: 8.0.22298)
TP-LINK Wireless Client Utility (x32 Version: 7.0)
TrueCrypt (x32 Version: 6.2a)
VLC media player 2.0.8 (x32 Version: 2.0.8)
Winamp (x32 Version: 5.65 )
Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1)
Windows Live ID Sign-in Assistant (Version: 6.500.3165.0)
WinRAR

==================== Restore Points  =========================

12-10-2013 15:07:47 DirectX wurde installiert

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {07BDB5E2-AA29-4B7C-91B8-71BB500A2A3E} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-08-30] (AVAST Software)
Task: {1640A659-5A2B-42FA-A5AC-614DEBF13519} - System32\Tasks\Feven 1.5-codedownloader => C:\Program Files (x86)\Feven 1.5\Feven 1.5-codedownloader.exe [2013-09-28] (Feven)
Task: {7C7EA6A6-2D24-4998-9FB9-14637657F46E} - System32\Tasks\Feven 1.5-chromeinstaller => C:\Program Files (x86)\Feven 1.5\Feven 1.5-chromeinstaller.exe [2013-09-28] (Feven)
Task: {8A84B245-5A9A-4591-BBD4-D06072565B50} - System32\Tasks\Feven 1.5-updater => C:\Program Files (x86)\Feven 1.5\Feven 1.5-updater.exe [2013-09-28] (Feven)
Task: {94D53870-9E08-47A6-B09E-A9833CB03411} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated)
Task: {9874408F-7AB0-4801-A87C-0818FB300148} - System32\Tasks\Feven 1.5-enabler => C:\Program Files (x86)\Feven 1.5\Feven 1.5-enabler.exe [2013-09-28] (Feven)
Task: {9D88740A-0025-4EF0-9F2F-4B94A1B21E8E} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: {B9DFD4D9-898B-44D1-81BB-293619554FC7} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
Task: {C49B32C5-483A-4C4A-9135-30E4A085EAD7} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: {D327A0ED-CDD5-43A3-8EC1-586FCBC839A0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-25] (Google Inc.)
Task: {E508E55C-2F35-4604-BD7A-E62EC5855868} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-25] (Google Inc.)
Task: {EDE4559D-3B9A-4EAE-AD25-2C03DA4048C1} - System32\Tasks\Feven 1.5-firefoxinstaller => C:\Program Files (x86)\Feven 1.5\Feven 1.5-firefoxinstaller.exe [2013-09-28] (Feven)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Feven 1.5-chromeinstaller.job => C:\Program Files (x86)\Feven 1.5\Feven 1.5-chromeinstaller.exe
Task: C:\Windows\Tasks\Feven 1.5-codedownloader.job => C:\Program Files (x86)\Feven 1.5\Feven 1.5-codedownloader.exe
Task: C:\Windows\Tasks\Feven 1.5-enabler.job => C:\Program Files (x86)\Feven 1.5\Feven 1.5-enabler.exe
Task: C:\Windows\Tasks\Feven 1.5-firefoxinstaller.job => C:\Program Files (x86)\Feven 1.5\Feven 1.5-firefoxinstaller.exe
Task: C:\Windows\Tasks\Feven 1.5-updater.job => C:\Program Files (x86)\Feven 1.5\Feven 1.5-updater.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2010-01-02 16:42 - 2010-01-02 16:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2009-08-26 10:38 - 2009-08-16 17:06 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll
2013-10-12 19:53 - 2013-10-12 17:00 - 02105856 _____ () C:\Program Files\AVAST Software\Avast\defs\13101200\algo.dll
2013-10-07 21:38 - 2013-05-16 10:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2013-10-07 21:38 - 2013-05-16 10:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2013-10-07 21:38 - 2013-05-16 10:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2013-10-07 21:38 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2013-10-07 21:38 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2013-03-13 22:48 - 2013-03-13 22:48 - 24978944 _____ () C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\libcef.dll
2012-07-25 18:41 - 2013-09-11 04:26 - 03279768 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\Users\Wild-Pako:zylomtest
AlternateDataStreams: C:\Users\Wild-Pako:zylomtr{000HQ7FF-AD7A-3FG1-QCPB-27EJ7OREQVVU}

==================== Safe Mode (whitelisted) ===================


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (10/09/2013 10:58:34 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: Need For Speed The Run.exe, Version: 1.0.0.0, Zeitstempel: 0x4eaa0448
Name des fehlerhaften Moduls: Need For Speed The Run.exe, Version: 1.0.0.0, Zeitstempel: 0x4eaa0448
Ausnahmecode: 0xc0000005
Fehleroffset: 0x012064b7
ID des fehlerhaften Prozesses: 0xaf8
Startzeit der fehlerhaften Anwendung: 0xNeed For Speed The Run.exe0
Pfad der fehlerhaften Anwendung: Need For Speed The Run.exe1
Pfad des fehlerhaften Moduls: Need For Speed The Run.exe2
Berichtskennung: Need For Speed The Run.exe3

Error: (10/09/2013 10:16:34 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: Need For Speed The Run.exe, Version: 1.0.0.0, Zeitstempel: 0x4eaa0448
Name des fehlerhaften Moduls: atidxx32.dll, Version: 8.17.10.519, Zeitstempel: 0x52212a54
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0007265b
ID des fehlerhaften Prozesses: 0x1820
Startzeit der fehlerhaften Anwendung: 0xNeed For Speed The Run.exe0
Pfad der fehlerhaften Anwendung: Need For Speed The Run.exe1
Pfad des fehlerhaften Moduls: Need For Speed The Run.exe2
Berichtskennung: Need For Speed The Run.exe3

Error: (10/09/2013 05:56:57 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: SDCleaner.exe, Version: 2.1.18.110, Zeitstempel: 0x51949f6e
Name des fehlerhaften Moduls: rtl150.bpl, Version: 15.0.3953.35171, Zeitstempel: 0x4cca139f
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000a116
ID des fehlerhaften Prozesses: 0x4fc
Startzeit der fehlerhaften Anwendung: 0xSDCleaner.exe0
Pfad der fehlerhaften Anwendung: SDCleaner.exe1
Pfad des fehlerhaften Moduls: SDCleaner.exe2
Berichtskennung: SDCleaner.exe3

Error: (10/08/2013 06:44:00 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: GTAIV.exe, Version: 1.0.7.0, Zeitstempel: 0x4bd9efbe
Name des fehlerhaften Moduls: atidxx32.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x52212a54
Ausnahmecode: 0xc0000005
Fehleroffset: 0x66aecce9
ID des fehlerhaften Prozesses: 0x13c8
Startzeit der fehlerhaften Anwendung: 0xGTAIV.exe0
Pfad der fehlerhaften Anwendung: GTAIV.exe1
Pfad des fehlerhaften Moduls: GTAIV.exe2
Berichtskennung: GTAIV.exe3

Error: (10/07/2013 08:14:05 PM) (Source: WinMgmt) (User: )
Description: 0x8004107aC:\WINDOWS\SYSTEM32\WBEM\SMTPCONS.MOF

Error: (10/07/2013 07:16:46 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: GTAIV.exe, Version: 1.0.7.0, Zeitstempel: 0x4bd9efbe
Name des fehlerhaften Moduls: QuickTime.qts_unloaded, Version: 0.0.0.0, Zeitstempel: 0x50890e53
Ausnahmecode: 0xc0000005
Fehleroffset: 0x60edcce9
ID des fehlerhaften Prozesses: 0x730
Startzeit der fehlerhaften Anwendung: 0xGTAIV.exe0
Pfad der fehlerhaften Anwendung: GTAIV.exe1
Pfad des fehlerhaften Moduls: GTAIV.exe2
Berichtskennung: GTAIV.exe3

Error: (10/03/2013 08:45:13 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: phoenixRC.exe, Version: 0.0.0.0, Zeitstempel: 0x51406972
Name des fehlerhaften Moduls: phnxdll.dll, Version: 0.0.0.0, Zeitstempel: 0x4b2a2720
Ausnahmecode: 0xc0000417
Fehleroffset: 0x00002d01
ID des fehlerhaften Prozesses: 0x1394
Startzeit der fehlerhaften Anwendung: 0xphoenixRC.exe0
Pfad der fehlerhaften Anwendung: phoenixRC.exe1
Pfad des fehlerhaften Moduls: phoenixRC.exe2
Berichtskennung: phoenixRC.exe3

Error: (10/03/2013 11:05:51 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: phoenixRC.exe, Version: 0.0.0.0, Zeitstempel: 0x4f784c98
Name des fehlerhaften Moduls: phnxdll.dll, Version: 0.0.0.0, Zeitstempel: 0x4b2a2720
Ausnahmecode: 0xc0000417
Fehleroffset: 0x00002d01
ID des fehlerhaften Prozesses: 0x10b0
Startzeit der fehlerhaften Anwendung: 0xphoenixRC.exe0
Pfad der fehlerhaften Anwendung: phoenixRC.exe1
Pfad des fehlerhaften Moduls: phoenixRC.exe2
Berichtskennung: phoenixRC.exe3

Error: (10/03/2013 10:35:58 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: phoenixRC.exe, Version: 0.0.0.0, Zeitstempel: 0x51406972
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x69747475
ID des fehlerhaften Prozesses: 0x13fc
Startzeit der fehlerhaften Anwendung: 0xphoenixRC.exe0
Pfad der fehlerhaften Anwendung: phoenixRC.exe1
Pfad des fehlerhaften Moduls: phoenixRC.exe2
Berichtskennung: phoenixRC.exe3

Error: (10/03/2013 10:30:30 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: phoenixRC.exe, Version: 0.0.0.0, Zeitstempel: 0x51406972
Name des fehlerhaften Moduls: phnxdll.dll, Version: 0.0.0.0, Zeitstempel: 0x4b2a2720
Ausnahmecode: 0xc0000417
Fehleroffset: 0x00002d01
ID des fehlerhaften Prozesses: 0x13f8
Startzeit der fehlerhaften Anwendung: 0xphoenixRC.exe0
Pfad der fehlerhaften Anwendung: phoenixRC.exe1
Pfad des fehlerhaften Moduls: phoenixRC.exe2
Berichtskennung: phoenixRC.exe3


System errors:
=============
Error: (10/12/2013 04:53:12 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (10/12/2013 04:53:12 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht.

Error: (10/11/2013 05:42:52 PM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (10/10/2013 10:52:30 PM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}

Error: (10/10/2013 06:56:03 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Update WebConnect" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (10/09/2013 06:45:41 PM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (10/09/2013 06:04:49 PM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (10/09/2013 05:55:53 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (10/09/2013 05:55:53 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht.

Error: (10/09/2013 05:49:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Überwachung verteilter Verknüpfungen (Client)" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1115


Microsoft Office Sessions:
=========================
Error: (10/09/2013 10:58:34 PM) (Source: Application Error)(User: )
Description: Need For Speed The Run.exe1.0.0.04eaa0448Need For Speed The Run.exe1.0.0.04eaa0448c0000005012064b7af801cec52e47418ff9K:\Program Files (x86)\NFS_Run\Need for Speed The Run\Need For Speed The Run.exeK:\Program Files (x86)\NFS_Run\Need for Speed The Run\Need For Speed The Run.exe8ee308b8-3125-11e3-8f7e-001fd08ec324

Error: (10/09/2013 10:16:34 PM) (Source: Application Error)(User: )
Description: Need For Speed The Run.exe1.0.0.04eaa0448atidxx32.dll8.17.10.51952212a54c00000050007265b182001cec5293d52a1beK:\Program Files (x86)\NFS_Run\Need for Speed The Run\Need For Speed The Run.exeC:\Windows\system32\atidxx32.dllb0f7c54c-311f-11e3-8f7e-001fd08ec324

Error: (10/09/2013 05:56:57 PM) (Source: Application Error)(User: )
Description: SDCleaner.exe2.1.18.11051949f6ertl150.bpl15.0.3953.351714cca139fc00000050000a1164fc01cec508237565eeC:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exeC:\Program Files (x86)\Spybot - Search & Destroy 2\rtl150.bpl6ca27701-30fb-11e3-b7d7-001fd08ec324

Error: (10/08/2013 06:44:00 PM) (Source: Application Error)(User: )
Description: GTAIV.exe1.0.7.04bd9efbeatidxx32.dll_unloaded0.0.0.052212a54c000000566aecce913c801cec444d8ad870eE:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV Complete Edition\GTAIV.exeatidxx32.dlld482db56-3038-11e3-a82d-001fd08ec324

Error: (10/07/2013 08:14:05 PM) (Source: WinMgmt)(User: )
Description: 0x8004107aC:\WINDOWS\SYSTEM32\WBEM\SMTPCONS.MOF

Error: (10/07/2013 07:16:46 PM) (Source: Application Error)(User: )
Description: GTAIV.exe1.0.7.04bd9efbeQuickTime.qts_unloaded0.0.0.050890e53c000000560edcce973001cec38076542fd4E:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV Complete Edition\GTAIV.exeQuickTime.qts3e32a351-2f74-11e3-9495-001fd08ec324

Error: (10/03/2013 08:45:13 PM) (Source: Application Error)(User: )
Description: phoenixRC.exe0.0.0.051406972phnxdll.dll0.0.0.04b2a2720c000041700002d01139401cec068b038094eK:\Program Files (x86)\PhoenixRC\phoenixRC.exeK:\Program Files (x86)\PhoenixRC\phnxdll.dllefce0472-2c5b-11e3-b0bd-001fd08ec324

Error: (10/03/2013 11:05:51 AM) (Source: Application Error)(User: )
Description: phoenixRC.exe0.0.0.04f784c98phnxdll.dll0.0.0.04b2a2720c000041700002d0110b001cec017c1535a9cD:\Program Files (x86)\PhoenixRC\phoenixRC.exeK:\Program Files (x86)\PhoenixRC\phnxdll.dllffa58662-2c0a-11e3-bd6e-001fd08ec324

Error: (10/03/2013 10:35:58 AM) (Source: Application Error)(User: )
Description: phoenixRC.exe0.0.0.051406972unknown0.0.0.000000000c00000056974747513fc01cec012d6ad7d63K:\Program Files (x86)\PhoenixRC\phoenixRC.exeunknownd339d1d7-2c06-11e3-bd6e-001fd08ec324

Error: (10/03/2013 10:30:30 AM) (Source: Application Error)(User: )
Description: phoenixRC.exe0.0.0.051406972phnxdll.dll0.0.0.04b2a2720c000041700002d0113f801cec012d0bb0888K:\Program Files (x86)\PhoenixRC\phoenixRC.exeK:\Program Files (x86)\PhoenixRC\phnxdll.dll0f896b00-2c06-11e3-bd6e-001fd08ec324


CodeIntegrity Errors:
===================================
  Date: 2012-11-10 18:09:59.681
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-11-10 18:04:32.048
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-11-01 14:45:50.678
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-11-01 14:19:27.887
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-11-01 14:09:36.725
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-25 19:57:25.923
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2012-10-25 19:43:49.397
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2011-07-26 20:19:10.501
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2011-07-23 11:12:49.613
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2011-07-23 11:05:30.782
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info =========================== 

Percentage of memory in use: 43%
Total physical RAM: 6142.49 MB
Available physical RAM: 3489.04 MB
Total Pagefile: 12283.17 MB
Available Pagefile: 9262.5 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:29.29 GB) (Free:5.47 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Transfer) (Fixed) (Total:200 GB) (Free:42.58 GB) NTFS
Drive e: (Daten_1) (Fixed) (Total:36.47 GB) (Free:5.79 GB) NTFS
Drive f: (Musik + Bilder) (Fixed) (Total:200 GB) (Free:125.25 GB) NTFS
Drive i: (NFS13) (CDROM) (Total:6.44 GB) (Free:0 GB) CDFS
Drive j: (USB HDD) (Fixed) (Total:148.82 GB) (Free:114.27 GB) FAT32
Drive k: (Daten_2) (Fixed) (Total:1397.26 GB) (Free:1098.38 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 0D5D0D5C)
Partition 1: (Active) - (Size=29 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=36 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=200 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=200 GB) - (Type=05)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1397 GB) (Disk ID: BA61BA15)
Partition 1: (Not Active) - (Size=-698723860480) - (Type=07 NTFS)

========================================================
Disk: 2 (Size: 149 GB) (Disk ID: 17E1D90B)

Partition: GPT Partition TypePartition 2: (Not Active) - (Size=149 GB) - (Type=0B)

==================== End Of Log ============================
         
__________________

Alt 13.10.2013, 00:00   #4
Wild-Pako
 
Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome - Standard

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome



Code:
ATTFilter
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-10-12 20:21:31
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-4 SAMSUNG_HD501LJ rev.CR100-11 465,76GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\WILD-P~1\AppData\Local\Temp\kxldquog.sys


---- User code sections - GMER 2.1 ----

.text   C:\Windows\system32\wininit.exe[584] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                               0000000077b6eecd 1 byte [62]
.text   C:\Windows\system32\services.exe[644] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                              0000000077b6eecd 1 byte [62]
.text   C:\Windows\system32\winlogon.exe[732] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                              0000000077b6eecd 1 byte [62]
.text   C:\Windows\system32\svchost.exe[816] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                               0000000077b6eecd 1 byte [62]
.text   C:\Windows\system32\atiesrxx.exe[120] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                              0000000077b6eecd 1 byte [62]
.text   C:\Windows\System32\svchost.exe[304] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                               0000000077b6eecd 1 byte [62]
.text   C:\Windows\System32\svchost.exe[472] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                               0000000077b6eecd 1 byte [62]
.text   C:\Windows\system32\svchost.exe[528] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                               0000000077b6eecd 1 byte [62]
.text   C:\Windows\system32\svchost.exe[600] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                               0000000077b6eecd 1 byte [62]
.text   C:\Windows\system32\svchost.exe[1324] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                              0000000077b6eecd 1 byte [62]
.text   C:\Windows\System32\spoolsv.exe[1748] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                              0000000077b6eecd 1 byte [62]
.text   C:\Windows\system32\svchost.exe[1776] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                              0000000077b6eecd 1 byte [62]
.text   C:\Program Files (x86)\DU Meter\DUMeterSvc.exe[1920] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                               000000007663a2ba 1 byte [62]
.text   C:\Windows\system32\svchost.exe[1960] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                              0000000077b6eecd 1 byte [62]
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[1008] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112               000000007663a2ba 1 byte [62]
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[1008] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69             0000000075e51465 2 bytes [E5, 75]
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[1008] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155            0000000075e514bb 2 bytes [E5, 75]
.text   ...                                                                                                                                      * 2
.text   C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                        0000000077c53b10 5 bytes JMP 00000001002e075c
.text   C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                          0000000077c57ac0 5 bytes JMP 00000001002e03a4
.text   C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                             0000000077c81430 5 bytes JMP 00000001002e0b14
.text   C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                 0000000077c81490 5 bytes JMP 00000001002e0ecc
.text   C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                  0000000077c81570 5 bytes JMP 00000001002e163c
.text   C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                              0000000077c817b0 5 bytes JMP 00000001002e1284
.text   C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                  0000000077c827e0 5 bytes JMP 00000001002e19f4
.text   C:\Windows\system32\taskhost.exe[2188] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                             0000000077b6eecd 1 byte [62]
.text   C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                          000007feffb66e00 5 bytes JMP 000007ff7fb81dac
.text   C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                              000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc
.text   C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                              000007feffb67220 5 bytes JMP 000007ff7fb81284
.text   C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                             000007feffb6739c 5 bytes JMP 000007ff7fb8163c
.text   C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                             000007feffb67538 5 bytes JMP 000007ff7fb819f4
.text   C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                    000007feffb675e8 5 bytes JMP 000007ff7fb803a4
.text   C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                    000007feffb6790c 5 bytes JMP 000007ff7fb8075c
.text   C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                     000007feffb67ab4 5 bytes JMP 000007ff7fb80b14
.text   C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                             0000000077c53b10 5 bytes JMP 000000010013075c
.text   C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                               0000000077c57ac0 5 bytes JMP 00000001001303a4
.text   C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                  0000000077c81430 5 bytes JMP 0000000100130b14
.text   C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                      0000000077c81490 5 bytes JMP 0000000100130ecc
.text   C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                       0000000077c81570 5 bytes JMP 000000010013163c
.text   C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                                   0000000077c817b0 5 bytes JMP 0000000100131284
.text   C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                       0000000077c827e0 5 bytes JMP 00000001001319f4
.text   C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                               000007feffb66e00 5 bytes JMP 000007ff7fb81dac
.text   C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                                   000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc
.text   C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                                   000007feffb67220 5 bytes JMP 000007ff7fb81284
.text   C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                                  000007feffb6739c 5 bytes JMP 000007ff7fb8163c
.text   C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                                  000007feffb67538 5 bytes JMP 000007ff7fb819f4
.text   C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                         000007feffb675e8 5 bytes JMP 000007ff7fb803a4
.text   C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                         000007feffb6790c 5 bytes JMP 000007ff7fb8075c
.text   C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                          000007feffb67ab4 5 bytes JMP 000007ff7fb80b14
.text   C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                 0000000077c53b10 5 bytes JMP 000000010017075c
.text   C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                   0000000077c57ac0 5 bytes JMP 00000001001703a4
.text   C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                      0000000077c81430 5 bytes JMP 0000000100170b14
.text   C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                          0000000077c81490 5 bytes JMP 0000000100170ecc
.text   C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                           0000000077c81570 5 bytes JMP 000000010017163c
.text   C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                                       0000000077c817b0 5 bytes JMP 0000000100171284
.text   C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                           0000000077c827e0 5 bytes JMP 00000001001719f4
.text   C:\Windows\Explorer.EXE[2320] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                                      0000000077b6eecd 1 byte [62]
.text   C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                                   000007feffb66e00 5 bytes JMP 000007ff7fb81dac
.text   C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                                       000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc
.text   C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                                       000007feffb67220 5 bytes JMP 000007ff7fb81284
.text   C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                                      000007feffb6739c 5 bytes JMP 000007ff7fb8163c
.text   C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                                      000007feffb67538 5 bytes JMP 000007ff7fb819f4
.text   C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                             000007feffb675e8 5 bytes JMP 000007ff7fb803a4
.text   C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                             000007feffb6790c 5 bytes JMP 000007ff7fb8075c
.text   C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                              000007feffb67ab4 5 bytes JMP 000007ff7fb80b14
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory            0000000077e2fac0 5 bytes JMP 0000000100030600
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory                0000000077e2fb58 5 bytes JMP 0000000100030804
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                 0000000077e2fcb0 5 bytes JMP 0000000100030c0c
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory             0000000077e30038 5 bytes JMP 0000000100030a08
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                 0000000077e31920 5 bytes JMP 0000000100030e10
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                         0000000077e4c4dd 5 bytes JMP 00000001000301f8
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                       0000000077e51287 5 bytes JMP 00000001000303fc
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112            000000007663a2ba 1 byte [62]
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity         0000000077925181 5 bytes JMP 0000000100201014
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA             0000000077925254 5 bytes JMP 0000000100200804
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW             00000000779253d5 5 bytes JMP 0000000100200a08
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A            00000000779254c2 5 bytes JMP 0000000100200c0c
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W            00000000779255e2 5 bytes JMP 0000000100200e10
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\sechost.dll!CreateServiceA                   000000007792567c 5 bytes JMP 00000001002001f8
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\sechost.dll!CreateServiceW                   000000007792589f 5 bytes JMP 00000001002003fc
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\sechost.dll!DeleteService                    0000000077925a22 5 bytes JMP 0000000100200600
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\syswow64\USER32.dll!SetWinEventHook                   0000000075fdee09 5 bytes JMP 00000001002101f8
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\syswow64\USER32.dll!UnhookWinEvent                    0000000075fe3982 5 bytes JMP 00000001002103fc
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                 0000000075fe7603 5 bytes JMP 0000000100210804
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                 0000000075fe835c 5 bytes JMP 0000000100210600
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx               0000000075fff52b 5 bytes JMP 0000000100210a08
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                 0000000077c53b10 5 bytes JMP 000000010019075c
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                   0000000077c57ac0 5 bytes JMP 00000001001903a4
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory      0000000077c81430 5 bytes JMP 0000000100190b14
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory          0000000077c81490 5 bytes JMP 0000000100190ecc
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess           0000000077c81570 5 bytes JMP 000000010019163c
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory       0000000077c817b0 5 bytes JMP 0000000100191284
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread           0000000077c827e0 5 bytes JMP 00000001001919f4
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189      0000000077b6eecd 1 byte [62]
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity   000007feffb66e00 5 bytes JMP 000007ff7fb81dac
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA       000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW       000007feffb67220 5 bytes JMP 000007ff7fb81284
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A      000007feffb6739c 5 bytes JMP 000007ff7fb8163c
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W      000007feffb67538 5 bytes JMP 000007ff7fb819f4
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA             000007feffb675e8 5 bytes JMP 000007ff7fb803a4
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW             000007feffb6790c 5 bytes JMP 000007ff7fb8075c
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\sechost.dll!DeleteService              000007feffb67ab4 5 bytes JMP 000007ff7fb80b14
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory              0000000077e2fac0 5 bytes JMP 0000000100030600
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory                  0000000077e2fb58 5 bytes JMP 0000000100030804
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                   0000000077e2fcb0 5 bytes JMP 0000000100030c0c
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory               0000000077e30038 5 bytes JMP 0000000100030a08
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                   0000000077e31920 5 bytes JMP 0000000100030e10
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                           0000000077e4c4dd 5 bytes JMP 00000001000301f8
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                         0000000077e51287 5 bytes JMP 00000001000303fc
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112              000000007663a2ba 1 byte [62]
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\syswow64\USER32.dll!SetWinEventHook                     0000000075fdee09 5 bytes JMP 00000001002401f8
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\syswow64\USER32.dll!UnhookWinEvent                      0000000075fe3982 5 bytes JMP 00000001002403fc
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                   0000000075fe7603 5 bytes JMP 0000000100240804
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                   0000000075fe835c 5 bytes JMP 0000000100240600
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx                 0000000075fff52b 5 bytes JMP 0000000100240a08
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity           0000000077925181 5 bytes JMP 0000000100251014
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA               0000000077925254 5 bytes JMP 0000000100250804
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW               00000000779253d5 5 bytes JMP 0000000100250a08
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A              00000000779254c2 5 bytes JMP 0000000100250c0c
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W              00000000779255e2 5 bytes JMP 0000000100250e10
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\sechost.dll!CreateServiceA                     000000007792567c 5 bytes JMP 00000001002501f8
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\sechost.dll!CreateServiceW                     000000007792589f 5 bytes JMP 00000001002503fc
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\sechost.dll!DeleteService                      0000000077925a22 5 bytes JMP 0000000100250600
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69            0000000075e51465 2 bytes [E5, 75]
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155           0000000075e514bb 2 bytes [E5, 75]
.text   ...                                                                                                                                      * 2
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2540] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity  000007feffb66e00 5 bytes JMP 000007ff7fb81dac
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2540] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA      000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2540] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW      000007feffb67220 5 bytes JMP 000007ff7fb81284
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2540] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A     000007feffb6739c 5 bytes JMP 000007ff7fb8163c
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2540] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W     000007feffb67538 5 bytes JMP 000007ff7fb819f4
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2540] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA            000007feffb675e8 5 bytes JMP 000007ff7fb803a4
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2540] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW            000007feffb6790c 5 bytes JMP 000007ff7fb8075c
.text   C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2540] C:\Windows\SYSTEM32\sechost.dll!DeleteService             000007feffb67ab4 5 bytes JMP 000007ff7fb80b14
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory              0000000077e2fac0 5 bytes JMP 0000000100030600
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory                  0000000077e2fb58 5 bytes JMP 0000000100030804
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                   0000000077e2fcb0 5 bytes JMP 0000000100030c0c
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory               0000000077e30038 5 bytes JMP 0000000100030a08
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                   0000000077e31920 5 bytes JMP 0000000100030e10
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                           0000000077e4c4dd 5 bytes JMP 00000001000301f8
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                         0000000077e51287 5 bytes JMP 00000001000303fc
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112              000000007663a2ba 1 byte [62]
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\syswow64\USER32.dll!SetWinEventHook                     0000000075fdee09 5 bytes JMP 00000001001001f8
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\syswow64\USER32.dll!UnhookWinEvent                      0000000075fe3982 5 bytes JMP 00000001001003fc
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                   0000000075fe7603 5 bytes JMP 0000000100100804
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                   0000000075fe835c 5 bytes JMP 0000000100100600
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx                 0000000075fff52b 5 bytes JMP 0000000100100a08
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity           0000000077925181 5 bytes JMP 0000000100151014
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA               0000000077925254 5 bytes JMP 0000000100150804
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW               00000000779253d5 5 bytes JMP 0000000100150a08
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A              00000000779254c2 5 bytes JMP 0000000100150c0c
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W              00000000779255e2 5 bytes JMP 0000000100150e10
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\sechost.dll!CreateServiceA                     000000007792567c 5 bytes JMP 00000001001501f8
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\sechost.dll!CreateServiceW                     000000007792589f 5 bytes JMP 00000001001503fc
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\sechost.dll!DeleteService                      0000000077925a22 5 bytes JMP 0000000100150600
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory                    0000000077e2fac0 5 bytes JMP 0000000100030600
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory                        0000000077e2fb58 5 bytes JMP 0000000100030804
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                         0000000077e2fcb0 5 bytes JMP 0000000100030c0c
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                     0000000077e30038 5 bytes JMP 0000000100030a08
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                         0000000077e31920 5 bytes JMP 0000000100030e10
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                 0000000077e4c4dd 5 bytes JMP 00000001000301f8
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                               0000000077e51287 5 bytes JMP 00000001000303fc
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                    000000007663a2ba 1 byte [62]
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity                 0000000077925181 5 bytes JMP 0000000100091014
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA                     0000000077925254 5 bytes JMP 0000000100090804
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW                     00000000779253d5 5 bytes JMP 0000000100090a08
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A                    00000000779254c2 5 bytes JMP 0000000100090c0c
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W                    00000000779255e2 5 bytes JMP 0000000100090e10
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\sechost.dll!CreateServiceA                           000000007792567c 5 bytes JMP 00000001000901f8
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\sechost.dll!CreateServiceW                           000000007792589f 5 bytes JMP 00000001000903fc
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\sechost.dll!DeleteService                            0000000077925a22 5 bytes JMP 0000000100090600
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\syswow64\USER32.dll!SetWinEventHook                           0000000075fdee09 5 bytes JMP 00000001000a01f8
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\syswow64\USER32.dll!UnhookWinEvent                            0000000075fe3982 5 bytes JMP 00000001000a03fc
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                         0000000075fe7603 5 bytes JMP 00000001000a0804
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                         0000000075fe835c 5 bytes JMP 00000001000a0600
.text   C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx                       0000000075fff52b 5 bytes JMP 00000001000a0a08
.text   C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                   0000000077c53b10 5 bytes JMP 000000010043075c
.text   C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                     0000000077c57ac0 5 bytes JMP 00000001004303a4
.text   C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                        0000000077c81430 5 bytes JMP 0000000100430b14
.text   C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                            0000000077c81490 5 bytes JMP 0000000100430ecc
.text   C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                             0000000077c81570 5 bytes JMP 000000010043163c
.text   C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                         0000000077c817b0 5 bytes JMP 0000000100431284
.text   C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                             0000000077c827e0 5 bytes JMP 00000001004319f4
.text   C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                        0000000077b6eecd 1 byte [62]
.text   C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                     000007feffb66e00 5 bytes JMP 000007ff7fb81dac
.text   C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                         000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc
.text   C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                         000007feffb67220 5 bytes JMP 000007ff7fb81284
.text   C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                        000007feffb6739c 5 bytes JMP 000007ff7fb8163c
.text   C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                        000007feffb67538 5 bytes JMP 000007ff7fb819f4
.text   C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                               000007feffb675e8 5 bytes JMP 000007ff7fb803a4
.text   C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                               000007feffb6790c 5 bytes JMP 000007ff7fb8075c
.text   C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                000007feffb67ab4 5 bytes JMP 000007ff7fb80b14
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                         0000000077c53b10 5 bytes JMP 00000001003f075c
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                           0000000077c57ac0 5 bytes JMP 00000001003f03a4
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                              0000000077c81430 5 bytes JMP 00000001003f0b14
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                  0000000077c81490 5 bytes JMP 00000001003f0ecc
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                   0000000077c81570 5 bytes JMP 00000001003f163c
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                               0000000077c817b0 5 bytes JMP 00000001003f1284
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                   0000000077c827e0 5 bytes JMP 00000001003f19f4
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                              0000000077b6eecd 1 byte [62]
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                           000007feffb66e00 5 bytes JMP 000007ff7fb81dac
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                               000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                               000007feffb67220 5 bytes JMP 000007ff7fb81284
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                              000007feffb6739c 5 bytes JMP 000007ff7fb8163c
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                              000007feffb67538 5 bytes JMP 000007ff7fb819f4
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                     000007feffb675e8 5 bytes JMP 000007ff7fb803a4
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                     000007feffb6790c 5 bytes JMP 000007ff7fb8075c
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                      000007feffb67ab4 5 bytes JMP 000007ff7fb80b14
.text   C:\Program Files (x86)\DU Meter\DUMeter.exe[3756] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory                                  0000000077e2fac0 5 bytes JMP 0000000100030600
.text   C:\Program Files (x86)\DU Meter\DUMeter.exe[3756] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory                                      0000000077e2fb58 5 bytes JMP 0000000100030804
.text   C:\Program Files (x86)\DU Meter\DUMeter.exe[3756] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                       0000000077e2fcb0 5 bytes JMP 0000000100030c0c
.text   C:\Program Files (x86)\DU Meter\DUMeter.exe[3756] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                   0000000077e30038 5 bytes JMP 0000000100030a08
.text   C:\Program Files (x86)\DU Meter\DUMeter.exe[3756] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                       0000000077e31920 5 bytes JMP 0000000100030e10
.text   C:\Program Files (x86)\DU Meter\DUMeter.exe[3756] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                               0000000077e4c4dd 5 bytes JMP 00000001000301f8
.text   C:\Program Files (x86)\DU Meter\DUMeter.exe[3756] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                             0000000077e51287 5 bytes JMP 00000001000303fc
.text   C:\Program Files (x86)\DU Meter\DUMeter.exe[3756] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                                  000000007663a2ba 1 byte [62]
.text   C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                            0000000077c53b10 5 bytes JMP 000000010010075c
.text   C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                              0000000077c57ac0 5 bytes JMP 00000001001003a4
.text   C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                 0000000077c81430 5 bytes JMP 0000000100100b14
.text   C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                     0000000077c81490 5 bytes JMP 0000000100100ecc
.text   C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                      0000000077c81570 5 bytes JMP 000000010010163c
.text   C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                  0000000077c817b0 5 bytes JMP 0000000100101284
.text   C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                      0000000077c827e0 5 bytes JMP 00000001001019f4
.text   C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                 0000000077b6eecd 1 byte [62]
.text   C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                              000007feffb66e00 5 bytes JMP 000007ff7fb81dac
.text   C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                  000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc
.text   C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                  000007feffb67220 5 bytes JMP 000007ff7fb81284
.text   C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                 000007feffb6739c 5 bytes JMP 000007ff7fb8163c
.text   C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                 000007feffb67538 5 bytes JMP 000007ff7fb819f4
.text   C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                        000007feffb675e8 5 bytes JMP 000007ff7fb803a4
.text   C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                        000007feffb6790c 5 bytes JMP 000007ff7fb8075c
.text   C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                         000007feffb67ab4 5 bytes JMP 000007ff7fb80b14
.text   C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                0000000077c53b10 5 bytes JMP 000000010020075c
.text   C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                  0000000077c57ac0 5 bytes JMP 00000001002003a4
.text   C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                     0000000077c81430 5 bytes JMP 0000000100200b14
.text   C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                         0000000077c81490 5 bytes JMP 0000000100200ecc
.text   C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                          0000000077c81570 5 bytes JMP 000000010020163c
.text   C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                      0000000077c817b0 5 bytes JMP 0000000100201284
.text   C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                          0000000077c827e0 5 bytes JMP 00000001002019f4
.text   C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                     0000000077b6eecd 1 byte [62]
.text   C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                  000007feffb66e00 5 bytes JMP 000007ff7fb81dac
.text   C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                      000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc
.text   C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                      000007feffb67220 5 bytes JMP 000007ff7fb81284
.text   C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                     000007feffb6739c 5 bytes JMP 000007ff7fb8163c
.text   C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                     000007feffb67538 5 bytes JMP 000007ff7fb819f4
.text   C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                            000007feffb675e8 5 bytes JMP 000007ff7fb803a4
.text   C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                            000007feffb6790c 5 bytes JMP 000007ff7fb8075c
.text   C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                             000007feffb67ab4 5 bytes JMP 000007ff7fb80b14
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory             0000000077e2fac0 5 bytes JMP 0000000100030600
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory                 0000000077e2fb58 5 bytes JMP 0000000100030804
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                  0000000077e2fcb0 5 bytes JMP 0000000100030c0c
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory              0000000077e30038 5 bytes JMP 0000000100030a08
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                  0000000077e31920 5 bytes JMP 0000000100030e10
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                          0000000077e4c4dd 5 bytes JMP 00000001000301f8
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                        0000000077e51287 5 bytes JMP 00000001000303fc
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112             000000007663a2ba 1 byte [62]
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity          0000000077925181 5 bytes JMP 0000000100251014
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA              0000000077925254 5 bytes JMP 0000000100250804
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW              00000000779253d5 5 bytes JMP 0000000100250a08
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A             00000000779254c2 5 bytes JMP 0000000100250c0c
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W             00000000779255e2 5 bytes JMP 0000000100250e10
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\sechost.dll!CreateServiceA                    000000007792567c 5 bytes JMP 00000001002501f8
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\sechost.dll!CreateServiceW                    000000007792589f 5 bytes JMP 00000001002503fc
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\sechost.dll!DeleteService                     0000000077925a22 5 bytes JMP 0000000100250600
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\syswow64\USER32.dll!SetWinEventHook                    0000000075fdee09 5 bytes JMP 00000001002601f8
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\syswow64\USER32.dll!UnhookWinEvent                     0000000075fe3982 5 bytes JMP 00000001002603fc
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                  0000000075fe7603 5 bytes JMP 0000000100260804
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                  0000000075fe835c 5 bytes JMP 0000000100260600
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx                0000000075fff52b 5 bytes JMP 0000000100260a08
.text   C:\Program Files\AVAST Software\Avast\AvastUI.exe[3992] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                            000000007663a2ba 1 byte [62]
.text   C:\Program Files\AVAST Software\Avast\AvastUI.exe[3992] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                          0000000075e51465 2 bytes [E5, 75]
.text   C:\Program Files\AVAST Software\Avast\AvastUI.exe[3992] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                         0000000075e514bb 2 bytes [E5, 75]
.text   ...                                                                                                                                      * 2
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory                   0000000077e2fac0 5 bytes JMP 0000000100030600
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory                       0000000077e2fb58 5 bytes JMP 0000000100030804
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                        0000000077e2fcb0 5 bytes JMP 0000000100030c0c
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                    0000000077e30038 5 bytes JMP 0000000100030a08
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                        0000000077e31920 5 bytes JMP 0000000100030e10
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                0000000077e4c4dd 5 bytes JMP 00000001000301f8
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                              0000000077e51287 5 bytes JMP 00000001000303fc
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                   000000007663a2ba 1 byte [62]
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\syswow64\USER32.dll!SetWinEventHook                          0000000075fdee09 5 bytes JMP 00000001002401f8
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\syswow64\USER32.dll!UnhookWinEvent                           0000000075fe3982 5 bytes JMP 00000001002403fc
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                        0000000075fe7603 5 bytes JMP 0000000100240804
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                        0000000075fe835c 5 bytes JMP 0000000100240600
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx                      0000000075fff52b 5 bytes JMP 0000000100240a08
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity                0000000077925181 5 bytes JMP 0000000100251014
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA                    0000000077925254 5 bytes JMP 0000000100250804
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW                    00000000779253d5 5 bytes JMP 0000000100250a08
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A                   00000000779254c2 5 bytes JMP 0000000100250c0c
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W                   00000000779255e2 5 bytes JMP 0000000100250e10
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\sechost.dll!CreateServiceA                          000000007792567c 5 bytes JMP 00000001002501f8
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\sechost.dll!CreateServiceW                          000000007792589f 5 bytes JMP 00000001002503fc
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\sechost.dll!DeleteService                           0000000077925a22 5 bytes JMP 0000000100250600
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 69                 0000000075e51465 2 bytes [E5, 75]
.text   C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 155                0000000075e514bb 2 bytes [E5, 75]
.text   ...                                                                                                                                      * 2
.text   C:\Windows\system32\svchost.exe[2432] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                           000007feffb66e00 5 bytes JMP 000007ff7fb81dac
.text   C:\Windows\system32\svchost.exe[2432] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                               000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc
.text   C:\Windows\system32\svchost.exe[2432] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                               000007feffb67220 5 bytes JMP 000007ff7fb81284
.text   C:\Windows\system32\svchost.exe[2432] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                              000007feffb6739c 5 bytes JMP 000007ff7fb8163c
.text   C:\Windows\system32\svchost.exe[2432] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                              000007feffb67538 5 bytes JMP 000007ff7fb819f4
.text   C:\Windows\system32\svchost.exe[2432] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                     000007feffb675e8 5 bytes JMP 000007ff7fb803a4
.text   C:\Windows\system32\svchost.exe[2432] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                     000007feffb6790c 5 bytes JMP 000007ff7fb8075c
.text   C:\Windows\system32\svchost.exe[2432] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                      000007feffb67ab4 5 bytes JMP 000007ff7fb80b14
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory                        0000000077e2fac0 5 bytes JMP 0000000100030600
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory                            0000000077e2fb58 5 bytes JMP 0000000100030804
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                             0000000077e2fcb0 5 bytes JMP 0000000100030c0c
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                         0000000077e30038 5 bytes JMP 0000000100030a08
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                             0000000077e31920 5 bytes JMP 0000000100030e10
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                     0000000077e4c4dd 5 bytes JMP 00000001000301f8
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                   0000000077e51287 5 bytes JMP 00000001000303fc
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                        000000007663a2ba 1 byte [62]
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity                     0000000077925181 5 bytes JMP 0000000100131014
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA                         0000000077925254 5 bytes JMP 0000000100130804
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW                         00000000779253d5 5 bytes JMP 0000000100130a08
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A                        00000000779254c2 5 bytes JMP 0000000100130c0c
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W                        00000000779255e2 5 bytes JMP 0000000100130e10
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\sechost.dll!CreateServiceA                               000000007792567c 5 bytes JMP 00000001001301f8
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\sechost.dll!CreateServiceW                               000000007792589f 5 bytes JMP 00000001001303fc
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\sechost.dll!DeleteService                                0000000077925a22 5 bytes JMP 0000000100130600
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                   0000000077c53b10 5 bytes JMP 00000001001c075c
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                     0000000077c57ac0 5 bytes JMP 00000001001c03a4
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                        0000000077c81430 5 bytes JMP 00000001001c0b14
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                            0000000077c81490 5 bytes JMP 00000001001c0ecc
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                             0000000077c81570 5 bytes JMP 00000001001c163c
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                         0000000077c817b0 5 bytes JMP 00000001001c1284
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                             0000000077c827e0 5 bytes JMP 00000001001c19f4
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                        0000000077b6eecd 1 byte [62]
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                     000007feffb66e00 5 bytes JMP 000007ff7fb81dac
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                         000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                         000007feffb67220 5 bytes JMP 000007ff7fb81284
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                        000007feffb6739c 5 bytes JMP 000007ff7fb8163c
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                        000007feffb67538 5 bytes JMP 000007ff7fb819f4
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                               000007feffb675e8 5 bytes JMP 000007ff7fb803a4
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                               000007feffb6790c 5 bytes JMP 000007ff7fb8075c
.text   C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                000007feffb67ab4 5 bytes JMP 000007ff7fb80b14
.text   C:\Program Files\Windows Media Player\wmpnetwk.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                      0000000077c53b10 5 bytes JMP 00000001002d075c
.text   C:\Program Files\Windows Media Player\wmpnetwk.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                        0000000077c57ac0 5 bytes JMP 00000001002d03a4
.text   C:\Program Files\Windows Media Player\wmpnetwk.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                           0000000077c81430 5 bytes JMP 00000001002d0b14
.text   C:\Program Files\Windows Media Player\wmpnetwk.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                               0000000077c81490 5 bytes JMP 00000001002d0ecc
.text   C:\Program Files\Windows Media Player\wmpnetwk.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                0000000077c81570 5 bytes JMP 00000001002d163c
.text   C:\Program Files\Windows Media Player\wmpnetwk.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                            0000000077c817b0 5 bytes JMP 00000001002d1284
.text   C:\Program Files\Windows Media Player\wmpnetwk.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                0000000077c827e0 5 bytes JMP 00000001002d19f4
.text   C:\Program Files\Windows Media Player\wmpnetwk.exe[4780] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                           0000000077b6eecd 1 byte [62]
.text   C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                         0000000077c53b10 5 bytes JMP 000000010017075c
.text   C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                           0000000077c57ac0 5 bytes JMP 00000001001703a4
.text   C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                              0000000077c81430 5 bytes JMP 0000000100170b14
.text   C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                  0000000077c81490 5 bytes JMP 0000000100170ecc
.text   C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                   0000000077c81570 5 bytes JMP 000000010017163c
.text   C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                               0000000077c817b0 5 bytes JMP 0000000100171284
.text   C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                   0000000077c827e0 5 bytes JMP 00000001001719f4
.text   C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                           000007feffb66e00 5 bytes JMP 000007ff7fb81dac
.text   C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                               000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc
.text   C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                               000007feffb67220 5 bytes JMP 000007ff7fb81284
.text   C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                              000007feffb6739c 5 bytes JMP 000007ff7fb8163c
.text   C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                              000007feffb67538 5 bytes JMP 000007ff7fb819f4
.text   C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                     000007feffb675e8 5 bytes JMP 000007ff7fb803a4
.text   C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                     000007feffb6790c 5 bytes JMP 000007ff7fb8075c
.text   C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                      000007feffb67ab4 5 bytes JMP 000007ff7fb80b14
.text   C:\Windows\System32\svchost.exe[4308] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                           000007feffb66e00 5 bytes JMP 000007ff7fb81dac
.text   C:\Windows\System32\svchost.exe[4308] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                               000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc
.text   C:\Windows\System32\svchost.exe[4308] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                               000007feffb67220 5 bytes JMP 000007ff7fb81284
.text   C:\Windows\System32\svchost.exe[4308] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                              000007feffb6739c 5 bytes JMP 000007ff7fb8163c
.text   C:\Windows\System32\svchost.exe[4308] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                              000007feffb67538 5 bytes JMP 000007ff7fb819f4
.text   C:\Windows\System32\svchost.exe[4308] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                     000007feffb675e8 5 bytes JMP 000007ff7fb803a4
.text   C:\Windows\System32\svchost.exe[4308] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                     000007feffb6790c 5 bytes JMP 000007ff7fb8075c
.text   C:\Windows\System32\svchost.exe[4308] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                      000007feffb67ab4 5 bytes JMP 000007ff7fb80b14
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory                                   0000000077e2fac0 5 bytes JMP 0000000100030600
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory                                       0000000077e2fb58 5 bytes JMP 0000000100030804
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                        0000000077e2fcb0 5 bytes JMP 0000000100030c0c
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                    0000000077e30038 5 bytes JMP 0000000100030a08
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                        0000000077e31920 5 bytes JMP 0000000100030e10
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                0000000077e4c4dd 5 bytes JMP 00000001000301f8
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                              0000000077e51287 5 bytes JMP 00000001000303fc
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                                   000000007663a2ba 1 byte [62]
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity                                0000000077925181 5 bytes JMP 0000000100241014
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA                                    0000000077925254 5 bytes JMP 0000000100240804
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW                                    00000000779253d5 5 bytes JMP 0000000100240a08
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A                                   00000000779254c2 5 bytes JMP 0000000100240c0c
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W                                   00000000779255e2 5 bytes JMP 0000000100240e10
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\sechost.dll!CreateServiceA                                          000000007792567c 5 bytes JMP 00000001002401f8
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\sechost.dll!CreateServiceW                                          000000007792589f 5 bytes JMP 00000001002403fc
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\sechost.dll!DeleteService                                           0000000077925a22 5 bytes JMP 0000000100240600
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                          0000000075fdee09 5 bytes JMP 00000001002501f8
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\syswow64\USER32.dll!UnhookWinEvent                                           0000000075fe3982 5 bytes JMP 00000001002503fc
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                        0000000075fe7603 5 bytes JMP 0000000100250804
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                        0000000075fe835c 5 bytes JMP 0000000100250600
.text   D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx                                      0000000075fff52b 5 bytes JMP 0000000100250a08

---- Threads - GMER 2.1 ----

Thread  C:\Windows\System32\svchost.exe [4308:2728]                                                                                              000007fee36a9688

---- Registry - GMER 2.1 ----

Reg     HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Type                                                                                     2
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Start                                                                                    2
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@ErrorControl                                                                             1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@DisplayName                                                                              aswFsBlk
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Group                                                                                    FSFilter Activity Monitor
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@DependOnService                                                                          FltMgr?
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Description                                                                              avast! mini-filter driver (aswFsBlk)
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Tag                                                                                      2
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances                                                                                
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances@DefaultInstance                                                                aswFsBlk Instance
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances\aswFsBlk Instance                                                              
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances\aswFsBlk Instance@Altitude                                                     388400
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances\aswFsBlk Instance@Flags                                                        0
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk                                                                                          
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Type                                                                                    2
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Start                                                                                   2
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@ErrorControl                                                                            1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@ImagePath                                                                               \??\C:\Windows\system32\drivers\aswMonFlt.sys
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@DisplayName                                                                             aswMonFlt
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Group                                                                                   FSFilter Anti-Virus
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@DependOnService                                                                         FltMgr?
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Description                                                                             avast! mini-filter driver (aswMonFlt)
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances                                                                               
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances@DefaultInstance                                                               aswMonFlt Instance
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance                                                            
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance@Altitude                                                   320700
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance@Flags                                                      0
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt                                                                                         
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRdr@ImagePath                                                                                  \SystemRoot\System32\Drivers\aswrdr2.sys
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Type                                                                                       1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Start                                                                                      1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRdr@ErrorControl                                                                               1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRdr@DisplayName                                                                                aswRdr
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Group                                                                                      PNP_TDI
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRdr@DependOnService                                                                            tcpip?
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Description                                                                                avast! WFP Redirect driver
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRdr\Parameters                                                                                 
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRdr\Parameters@MSIgnoreLSPDefault                                                              
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRdr\Parameters@WSIgnoreLSPDefault                                                              nl_lsp.dll,imon.dll,xfire_lsp.dll,mslsp.dll,mssplsp.dll,cwhook.dll,spi.dll,bmnet.dll,winsflt.dll
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRdr                                                                                            
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@Type                                                                                      1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@Start                                                                                     0
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@ErrorControl                                                                              1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@DisplayName                                                                               aswRvrt
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@Description                                                                               avast! Revert
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters                                                                                
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@BootCounter                                                                    9
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@TickCounter                                                                    77010
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@SystemRoot                                                                     \Device\Harddisk0\Partition1\Windows
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@ImproperShutdown                                                               1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswRvrt                                                                                           
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Type                                                                                       2
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Start                                                                                      1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSnx@ErrorControl                                                                               1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSnx@DisplayName                                                                                aswSnx
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Group                                                                                      FSFilter Virtualization
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSnx@DependOnService                                                                            FltMgr?
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Description                                                                                avast! virtualization driver (aswSnx)
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Tag                                                                                        2
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances                                                                                  
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances@DefaultInstance                                                                  aswSnx Instance
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance                                                                  
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance@Altitude                                                         137600
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance@Flags                                                            0
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Parameters                                                                                 
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Parameters@ProgramFolder                                                                   \DosDevices\C:\Program Files\AVAST Software\Avast
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Parameters@DataFolder                                                                      \DosDevices\C:\ProgramData\AVAST Software\Avast
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSnx                                                                                            
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSP@Type                                                                                        1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSP@Start                                                                                       1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSP@ErrorControl                                                                                1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSP@DisplayName                                                                                 aswSP
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSP@Description                                                                                 avast! Self Protection
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters                                                                                  
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@BehavShield                                                                      1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@ProgramFolder                                                                    \DosDevices\C:\Program Files\AVAST Software\Avast
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@DataFolder                                                                       \DosDevices\C:\ProgramData\AVAST Software\Avast
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@ProgramFilesFolder                                                               \DosDevices\C:\Program Files
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@GadgetFolder                                                                     \DosDevices\C:\Program Files\Windows Sidebar\Shared Gadgets\aswSidebar.gadget
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswSP                                                                                             
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Type                                                                                       1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Start                                                                                      1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswTdi@ErrorControl                                                                               1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswTdi@DisplayName                                                                                avast! Network Shield Support
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Group                                                                                      PNP_TDI
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswTdi@DependOnService                                                                            tcpip?
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Description                                                                                avast! Network Shield TDI driver
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Tag                                                                                        8
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswTdi                                                                                            
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswVmm@Type                                                                                       1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswVmm@Start                                                                                      0
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswVmm@ErrorControl                                                                               1
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswVmm@DisplayName                                                                                aswVmm
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswVmm@Description                                                                                avast! VM Monitor
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswVmm\Parameters                                                                                 
Reg     HKLM\SYSTEM\CurrentControlSet\services\aswVmm                                                                                            
Reg     HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Type                                                                             32
Reg     HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Start                                                                            2
Reg     HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ErrorControl                                                                     1
Reg     HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ImagePath                                                                        "C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
Reg     HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@DisplayName                                                                      avast! Antivirus
Reg     HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Group                                                                            ShellSvcGroup
Reg     HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@DependOnService                                                                  aswMonFlt?RpcSS?
Reg     HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@WOW64                                                                            1
Reg     HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ObjectName                                                                       LocalSystem
Reg     HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ServiceSidType                                                                   1
Reg     HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Description                                                                      Verwaltet und implementiert avast! Antivirus-Dienste f?r diesen Computer. Dies beinhaltet den Echtzeit-Schutz, den Virus-Container und den Planer.
Reg     HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus                                                                                  
Reg     HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Type                                                                                         2
Reg     HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Start                                                                                        2
Reg     HKLM\SYSTEM\ControlSet002\services\aswFsBlk@ErrorControl                                                                                 1
Reg     HKLM\SYSTEM\ControlSet002\services\aswFsBlk@DisplayName                                                                                  aswFsBlk
Reg     HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Group                                                                                        FSFilter Activity Monitor
Reg     HKLM\SYSTEM\ControlSet002\services\aswFsBlk@DependOnService                                                                              FltMgr?
Reg     HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Description                                                                                  avast! mini-filter driver (aswFsBlk)
Reg     HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Tag                                                                                          2
Reg     HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances (not active ControlSet)                                                            
Reg     HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances@DefaultInstance                                                                    aswFsBlk Instance
Reg     HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances\aswFsBlk Instance (not active ControlSet)                                          
Reg     HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances\aswFsBlk Instance@Altitude                                                         388400
Reg     HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances\aswFsBlk Instance@Flags                                                            0
Reg     HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Type                                                                                        2
Reg     HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Start                                                                                       2
Reg     HKLM\SYSTEM\ControlSet002\services\aswMonFlt@ErrorControl                                                                                1
Reg     HKLM\SYSTEM\ControlSet002\services\aswMonFlt@ImagePath                                                                                   \??\C:\Windows\system32\drivers\aswMonFlt.sys
Reg     HKLM\SYSTEM\ControlSet002\services\aswMonFlt@DisplayName                                                                                 aswMonFlt
Reg     HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Group                                                                                       FSFilter Anti-Virus
Reg     HKLM\SYSTEM\ControlSet002\services\aswMonFlt@DependOnService                                                                             FltMgr?
Reg     HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Description                                                                                 avast! mini-filter driver (aswMonFlt)
Reg     HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances (not active ControlSet)                                                           
Reg     HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances@DefaultInstance                                                                   aswMonFlt Instance
Reg     HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances\aswMonFlt Instance (not active ControlSet)                                        
Reg     HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances\aswMonFlt Instance@Altitude                                                       320700
Reg     HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances\aswMonFlt Instance@Flags                                                          0
Reg     HKLM\SYSTEM\ControlSet002\services\aswRdr@ImagePath                                                                                      \SystemRoot\System32\Drivers\aswrdr2.sys
Reg     HKLM\SYSTEM\ControlSet002\services\aswRdr@Type                                                                                           1
Reg     HKLM\SYSTEM\ControlSet002\services\aswRdr@Start                                                                                          1
Reg     HKLM\SYSTEM\ControlSet002\services\aswRdr@ErrorControl                                                                                   1
Reg     HKLM\SYSTEM\ControlSet002\services\aswRdr@DisplayName                                                                                    aswRdr
Reg     HKLM\SYSTEM\ControlSet002\services\aswRdr@Group                                                                                          PNP_TDI
Reg     HKLM\SYSTEM\ControlSet002\services\aswRdr@DependOnService                                                                                tcpip?
Reg     HKLM\SYSTEM\ControlSet002\services\aswRdr@Description                                                                                    avast! WFP Redirect driver
Reg     HKLM\SYSTEM\ControlSet002\services\aswRdr\Parameters (not active ControlSet)                                                             
Reg     HKLM\SYSTEM\ControlSet002\services\aswRdr\Parameters@MSIgnoreLSPDefault                                                                  
Reg     HKLM\SYSTEM\ControlSet002\services\aswRdr\Parameters@WSIgnoreLSPDefault                                                                  nl_lsp.dll,imon.dll,xfire_lsp.dll,mslsp.dll,mssplsp.dll,cwhook.dll,spi.dll,bmnet.dll,winsflt.dll
Reg     HKLM\SYSTEM\ControlSet002\services\aswRvrt@Type                                                                                          1
Reg     HKLM\SYSTEM\ControlSet002\services\aswRvrt@Start                                                                                         0
Reg     HKLM\SYSTEM\ControlSet002\services\aswRvrt@ErrorControl                                                                                  1
Reg     HKLM\SYSTEM\ControlSet002\services\aswRvrt@DisplayName                                                                                   aswRvrt
Reg     HKLM\SYSTEM\ControlSet002\services\aswRvrt@Description                                                                                   avast! Revert
Reg     HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters (not active ControlSet)                                                            
Reg     HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@BootCounter                                                                        9
Reg     HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@TickCounter                                                                        77010
Reg     HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@SystemRoot                                                                         \Device\Harddisk0\Partition1\Windows
Reg     HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@ImproperShutdown                                                                   1
Reg     HKLM\SYSTEM\ControlSet002\services\aswSnx@Type                                                                                           2
Reg     HKLM\SYSTEM\ControlSet002\services\aswSnx@Start                                                                                          1
Reg     HKLM\SYSTEM\ControlSet002\services\aswSnx@ErrorControl                                                                                   1
Reg     HKLM\SYSTEM\ControlSet002\services\aswSnx@DisplayName                                                                                    aswSnx
Reg     HKLM\SYSTEM\ControlSet002\services\aswSnx@Group                                                                                          FSFilter Virtualization
Reg     HKLM\SYSTEM\ControlSet002\services\aswSnx@DependOnService                                                                                FltMgr?
Reg     HKLM\SYSTEM\ControlSet002\services\aswSnx@Description                                                                                    avast! virtualization driver (aswSnx)
Reg     HKLM\SYSTEM\ControlSet002\services\aswSnx@Tag                                                                                            2
Reg     HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances (not active ControlSet)                                                              
Reg     HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances@DefaultInstance                                                                      aswSnx Instance
Reg     HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances\aswSnx Instance (not active ControlSet)                                              
Reg     HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances\aswSnx Instance@Altitude                                                             137600
Reg     HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances\aswSnx Instance@Flags                                                                0
Reg     HKLM\SYSTEM\ControlSet002\services\aswSnx\Parameters (not active ControlSet)                                                             
Reg     HKLM\SYSTEM\ControlSet002\services\aswSnx\Parameters@ProgramFolder                                                                       \DosDevices\C:\Program Files\AVAST Software\Avast
Reg     HKLM\SYSTEM\ControlSet002\services\aswSnx\Parameters@DataFolder                                                                          \DosDevices\C:\ProgramData\AVAST Software\Avast
Reg     HKLM\SYSTEM\ControlSet002\services\aswSP@Type                                                                                            1
Reg     HKLM\SYSTEM\ControlSet002\services\aswSP@Start                                                                                           1
Reg     HKLM\SYSTEM\ControlSet002\services\aswSP@ErrorControl                                                                                    1
Reg     HKLM\SYSTEM\ControlSet002\services\aswSP@DisplayName                                                                                     aswSP
Reg     HKLM\SYSTEM\ControlSet002\services\aswSP@Description                                                                                     avast! Self Protection
Reg     HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters (not active ControlSet)                                                              
Reg     HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@BehavShield                                                                          1
Reg     HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@ProgramFolder                                                                        \DosDevices\C:\Program Files\AVAST Software\Avast
Reg     HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@DataFolder                                                                           \DosDevices\C:\ProgramData\AVAST Software\Avast
Reg     HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@ProgramFilesFolder                                                                   \DosDevices\C:\Program Files
Reg     HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@GadgetFolder                                                                         \DosDevices\C:\Program Files\Windows Sidebar\Shared Gadgets\aswSidebar.gadget
Reg     HKLM\SYSTEM\ControlSet002\services\aswTdi@Type                                                                                           1
Reg     HKLM\SYSTEM\ControlSet002\services\aswTdi@Start                                                                                          1
Reg     HKLM\SYSTEM\ControlSet002\services\aswTdi@ErrorControl                                                                                   1
Reg     HKLM\SYSTEM\ControlSet002\services\aswTdi@DisplayName                                                                                    avast! Network Shield Support
Reg     HKLM\SYSTEM\ControlSet002\services\aswTdi@Group                                                                                          PNP_TDI
Reg     HKLM\SYSTEM\ControlSet002\services\aswTdi@DependOnService                                                                                tcpip?
Reg     HKLM\SYSTEM\ControlSet002\services\aswTdi@Description                                                                                    avast! Network Shield TDI driver
Reg     HKLM\SYSTEM\ControlSet002\services\aswTdi@Tag                                                                                            8
Reg     HKLM\SYSTEM\ControlSet002\services\aswVmm@Type                                                                                           1
Reg     HKLM\SYSTEM\ControlSet002\services\aswVmm@Start                                                                                          0
Reg     HKLM\SYSTEM\ControlSet002\services\aswVmm@ErrorControl                                                                                   1
Reg     HKLM\SYSTEM\ControlSet002\services\aswVmm@DisplayName                                                                                    aswVmm
Reg     HKLM\SYSTEM\ControlSet002\services\aswVmm@Description                                                                                    avast! VM Monitor
Reg     HKLM\SYSTEM\ControlSet002\services\aswVmm\Parameters (not active ControlSet)                                                             
Reg     HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Type                                                                                 32
Reg     HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Start                                                                                2
Reg     HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ErrorControl                                                                         1
Reg     HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ImagePath                                                                            "C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
Reg     HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@DisplayName                                                                          avast! Antivirus
Reg     HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Group                                                                                ShellSvcGroup
Reg     HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@DependOnService                                                                      aswMonFlt?RpcSS?
Reg     HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@WOW64                                                                                1
Reg     HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ObjectName                                                                           LocalSystem
Reg     HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ServiceSidType                                                                       1
Reg     HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Description                                                                          Verwaltet und implementiert avast! Antivirus-Dienste f?r diesen Computer. Dies beinhaltet den Echtzeit-Schutz, den Virus-Container und den Planer.

---- EOF - GMER 2.1 ----
         
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013
Ran by Wild-Pako (administrator) on WILD-PAKO-PC on 12-10-2013 20:10:26
Running from D:\! - - Transfer - - !
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Hagel Technologies Ltd.) C:\Program Files (x86)\DU Meter\DUMeterSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Hagel Technologies Ltd.) C:\Program Files (x86)\DU Meter\DUMeter.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
() C:\Program Files\Core Temp\Core Temp.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Dropbox, Inc.) C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7883296 2009-06-25] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-06-25] (Realtek Semiconductor Corp.)
HKCU\...\Run: [Remote Control Editor] - "C:\Program Files (x86)\Common Files\TerraTec\Remote\TTTvRc.exe"
HKCU\...\Run: [MobileDocuments] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
HKCU\...\Run: [DU Meter] - C:\Program Files (x86)\DU Meter\DUMeter.exe [2749984 2013-09-27] (Hagel Technologies Ltd.)
HKCU\...\Run: [CrossLoop] - "C:\Users\Wild-Pako\AppData\Local\CrossLoop\CrossLoopConnect.exe" -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server -noprompts -minimize
HKCU\...\Run: [Spybot-S&D Cleaning] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3642312 2013-05-16] (Safer-Networking Ltd.)
MountPoints2: {5711135d-b34d-11de-b593-001fd08ec324} - I:\AutoRun.exe
MountPoints2: {57111360-b34d-11de-b593-001fd08ec324} - I:\AutoRun.exe
MountPoints2: {ad02c2d2-a265-11df-a90c-001fd08ec324} - I:\AutoRun.exe
MountPoints2: {df46a678-1ebf-11e2-b35a-001fd08ec324} - I:\Setup.exe
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-08-30] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software)
Startup: C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Core Temp.lnk
ShortcutTarget: Core Temp.lnk -> C:\Program Files\Core Temp\Core Temp.exe ()
Startup: C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=6CFE001FD08EC324&affID=120523&tt=240913_238&tsp=5019
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x01E862F5F4B9CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1286050903776
DPF: HKLM-x32 {971FC730-55F1-461F-83FD-B3BF5E1F039E} hxxp://wg.dyndns.ws/AVC_AX_742.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2

FireFox:
========
FF ProfilePath: C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\249911bc-d1bd-4d66-8c17-df533609e6d8@c76f3de9-939e-4922-b73c-5d7a3139375d.com
FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\foxmarks@kei.com
FF Extension: VLC Media Player - Web Plugin - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\vlcplugin@radicalsoft.com
FF Extension: Flagfox - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
FF Extension: Flashblock - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
FF Extension: adblockpopups - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\adblockpopups@jessehakanen.net.xpi
FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi
FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}.xpi
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
         

Alt 13.10.2013, 00:05   #5
Wild-Pako
 
Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome - Standard

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome



Code:
ATTFilter
Chrome: 
=======
CHR HomePage: hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=6CFE001FD08EC324&affID=120523&tt=240913_238&tsp=5019
CHR RestoreOnStartup: "hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=6CFE001FD08EC324&affID=119357&tt=240913_246&tsp=5016"
CHR DefaultSearchURL: (SearchGol) - hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=6CFE001FD08EC324&affID=120523&tt=240913_238&tsp=5019
CHR DefaultSuggestURL: (SearchGol) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U40) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll No File
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll No File
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.400.43) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (Google Docs) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (Feven 1.5) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.24.28_0
CHR Extension: (YouTube) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR Extension: (Gmail) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software)
R2 DUMeterSvc; C:\Program Files (x86)\DU Meter\DUMeterSvc.exe [1391136 2009-09-04] (Hagel Technologies Ltd.)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.)
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [x]

==================== Drivers (Whitelisted) ====================

R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-10-25] (DT Soft Ltd)
S3 gdrv; C:\Windows\gdrv.sys [25640 2013-10-03] (Windows (R) Server 2003 DDK provider)
S3 gdrv; C:\Windows\gdrv.sys [25640 2013-10-03] (Windows (R) Server 2003 DDK provider)
S3 MTSBDA; C:\Windows\System32\DRIVERS\MtsBda.sys [322080 2008-12-01] (TerraTec Provide)
S3 MtsHID; C:\Windows\System32\DRIVERS\MtsHid.sys [27168 2008-12-01] (TerraTec Provide)
S1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R1 truecrypt; C:\Windows\SysWow64\drivers\truecrypt.sys [221376 2009-08-15] (TrueCrypt Foundation)
R1 truecrypt; C:\Windows\SysWow64\drivers\truecrypt.sys [221376 2009-08-15] (TrueCrypt Foundation)
R3 ALSysIO; \??\C:\Users\WILD-P~1\AppData\Local\Temp\ALSysIO64.sys [x]
S3 cpuz135; \??\C:\Users\WILD-P~1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [x]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x]
S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [x]
S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-10-12 20:10 - 2013-10-12 20:10 - 00000000 ____D C:\FRST
2013-10-12 20:09 - 2013-10-12 20:09 - 00000168 _____ C:\Users\Wild-Pako\defogger_reenable
2013-10-12 19:48 - 2013-10-12 19:49 - 00000000 ____D C:\AdwCleaner
2013-10-12 17:08 - 2013-10-12 17:08 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\SCE
2013-10-12 17:07 - 2013-10-12 17:07 - 00000810 _____ C:\Users\Wild-Pako\Desktop\PlanetSide 2 PSG.lnk
2013-10-12 17:07 - 2013-10-12 17:07 - 00000810 _____ C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlanetSide 2 PSG.lnk
2013-10-10 19:02 - 2013-10-10 19:02 - 00001084 _____ C:\Users\Public\Desktop\Need for Speed Most Wanted.lnk
2013-10-09 21:53 - 2013-10-09 21:54 - 00000000 ____D C:\Users\Wild-Pako\Documents\NFSTR
2013-10-09 18:24 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-09 18:24 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-10-09 18:24 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-09 18:24 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-09 18:24 - 2013-09-23 00:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-10-09 18:24 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-10-09 18:24 - 2013-09-21 05:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-09 18:24 - 2013-09-21 05:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-09 18:24 - 2013-09-21 04:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-10-09 18:24 - 2013-09-21 04:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-10-09 18:03 - 2013-09-04 14:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-09 18:03 - 2013-09-04 14:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-09 18:03 - 2013-09-04 14:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-09 18:03 - 2013-09-04 14:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-09 18:03 - 2013-09-04 14:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-10-09 18:03 - 2013-09-04 14:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-10-09 18:03 - 2013-09-04 14:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-09 18:03 - 2013-08-28 03:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-09 18:03 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-09 18:03 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-09 18:03 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-09 18:03 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-09 18:03 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-09 18:03 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-09 18:03 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-09 18:03 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-09 18:03 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-09 18:03 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-10-09 18:03 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-10-09 18:03 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-10-09 18:03 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-09 18:03 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2013-10-09 18:03 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2013-10-09 18:03 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2013-10-09 18:03 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-09 18:03 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-09 18:03 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-08 21:32 - 2013-10-08 21:32 - 00001374 _____ C:\Users\Wild-Pako\Desktop\farcry3.lnk
2013-10-08 21:32 - 2013-10-08 21:32 - 00000000 ____D C:\Users\Wild-Pako\Documents\My Games
2013-10-08 21:32 - 2013-10-08 21:32 - 00000000 ____D C:\ProgramData\Orbit
2013-10-08 20:39 - 2013-10-08 20:39 - 00001513 _____ C:\Users\Wild-Pako\Desktop\Need For Speed The Run.lnk
2013-10-08 19:58 - 2013-10-12 19:52 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-10-08 19:58 - 2013-10-08 19:58 - 00001922 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-10-08 19:58 - 2013-08-30 09:48 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-10-08 19:58 - 2013-08-30 09:48 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-10-08 19:58 - 2013-08-30 09:48 - 00204880 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-10-08 19:58 - 2013-08-30 09:48 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-10-08 19:58 - 2013-08-30 09:48 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2013-10-08 19:58 - 2013-08-30 09:48 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-10-08 19:58 - 2013-08-30 09:48 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2013-10-08 19:58 - 2013-08-30 09:48 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys
2013-10-08 19:58 - 2013-08-30 09:47 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-10-08 19:56 - 2013-10-08 19:56 - 00000000 ____D C:\Program Files\AVAST Software
2013-10-08 19:56 - 2013-08-30 09:47 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-10-08 19:52 - 2013-10-08 19:56 - 00000000 ____D C:\ProgramData\AVAST Software
2013-10-08 19:08 - 2013-10-08 19:08 - 00000000 ____D C:\ProgramData\Futuremark
2013-10-08 19:07 - 2013-10-08 19:07 - 00000924 _____ C:\Users\Public\Desktop\3DMark Vantage.lnk
2013-10-08 19:06 - 2013-10-08 19:06 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-10-08 19:06 - 2013-10-08 19:06 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-10-07 21:59 - 2013-10-07 22:09 - 00001760 _____ C:\Windows\wininit.ini
2013-10-07 21:57 - 2013-10-07 21:57 - 00007601 _____ C:\Users\Wild-Pako\AppData\Local\Resmon.ResmonCfg
2013-10-07 21:38 - 2013-10-07 21:59 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-10-07 21:38 - 2013-10-07 21:39 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-10-07 21:38 - 2013-10-07 21:38 - 00001343 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-10-07 21:38 - 2013-10-07 21:38 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-10-07 21:38 - 2009-01-25 13:14 - 00017272 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2013-10-07 19:10 - 2013-10-07 19:10 - 00000000 ____D C:\ProgramData\ATI
2013-10-07 18:58 - 2013-10-07 18:58 - 00055617 _____ C:\Windows\SysWOW64\CCCInstall_201310071858030463.log
2013-10-07 18:58 - 2013-10-07 18:58 - 00000000 ____D C:\ProgramData\AMD
2013-10-07 18:58 - 2013-10-07 18:58 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2013-10-07 18:56 - 2013-10-07 18:56 - 00018620 _____ C:\Windows\SysWOW64\CCCInstall_201310071856358562.log
2013-10-07 18:55 - 2013-10-07 18:55 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2013-10-07 18:52 - 2013-10-07 18:53 - 00000000 ____D C:\ProgramData\Package Cache
2013-10-06 23:20 - 2013-10-06 23:20 - 00000045 _____ C:\Users\Wild-Pako\Desktop\Neues Textdokument.txt
2013-10-03 18:20 - 2013-10-03 18:26 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
2013-10-03 15:26 - 2008-09-24 10:38 - 01048576 _____ C:\Users\Wild-Pako\ep43ds3.f9
2013-10-03 15:26 - 2008-08-28 09:16 - 00026351 _____ C:\Users\Wild-Pako\FLASHSPI.EXE
2013-10-03 13:51 - 2013-10-03 14:47 - 00037130 _____ C:\pingstat.txt
2013-10-03 13:49 - 2013-10-03 13:50 - 00000332 _____ C:\Users\Wild-Pako\Desktop\Neues Textdokument.bat
2013-10-03 10:26 - 2013-10-03 10:26 - 00001160 _____ C:\Users\Wild-Pako\Desktop\launcher - Verknüpfung.lnk
2013-10-02 23:03 - 2013-10-02 23:03 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Sinvise Systems
2013-10-02 23:03 - 2013-10-02 23:03 - 00000000 ____D C:\Program Files (x86)\Sinvise Systems
2013-10-02 21:26 - 2013-10-02 21:27 - 00000000 ____D C:\Users\Wild-Pako\Documents\NFS Undercover
2013-10-02 21:24 - 2013-10-02 21:24 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Leadertech
2013-10-02 21:06 - 2013-10-10 19:08 - 00000000 ____D C:\Users\Wild-Pako\Documents\Criterion Games
2013-10-02 21:06 - 2013-10-02 21:06 - 00000000 ____D C:\ProgramData\Electronic Arts
2013-10-02 21:06 - 2013-10-02 21:06 - 00000000 ____D C:\ProgramData\EA Core
2013-10-01 12:42 - 2013-10-07 22:10 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\CrossLoop
2013-09-29 14:07 - 2013-10-11 19:53 - 00000000 ____D C:\Windows\Minidump
2013-09-29 13:45 - 2013-09-29 13:48 - 00000000 ____D C:\Users\Wild-Pako\Desktop\Prime95
2013-09-29 13:43 - 2013-09-29 13:43 - 00000948 _____ C:\Users\Wild-Pako\Desktop\Core Temp.lnk
2013-09-29 11:43 - 2013-09-29 11:43 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-09-29 11:39 - 2013-10-03 10:23 - 00000000 ____D C:\Users\Wild-Pako\Documents\PhoenixRC
2013-09-29 11:35 - 2013-10-03 10:25 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhoenixRC
2013-09-28 22:33 - 2013-10-12 19:51 - 00001286 _____ C:\Windows\Tasks\Feven 1.5-updater.job
2013-09-28 22:33 - 2013-10-12 19:51 - 00001190 _____ C:\Windows\Tasks\Feven 1.5-codedownloader.job
2013-09-28 22:33 - 2013-10-12 19:51 - 00001090 _____ C:\Windows\Tasks\Feven 1.5-enabler.job
2013-09-28 22:33 - 2013-09-28 22:33 - 00004316 _____ C:\Windows\System32\Tasks\Feven 1.5-updater
2013-09-28 22:33 - 2013-09-28 22:33 - 00004220 _____ C:\Windows\System32\Tasks\Feven 1.5-codedownloader
2013-09-28 22:33 - 2013-09-28 22:33 - 00004120 _____ C:\Windows\System32\Tasks\Feven 1.5-enabler
2013-09-28 22:32 - 2013-10-12 19:51 - 00001818 _____ C:\Windows\Tasks\Feven 1.5-firefoxinstaller.job
2013-09-28 22:32 - 2013-09-28 22:32 - 00000869 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2013-09-28 22:32 - 2013-09-28 22:32 - 00000000 ____D C:\Program Files\CPUID
2013-09-28 22:31 - 2013-10-12 19:51 - 00001894 _____ C:\Windows\Tasks\Feven 1.5-chromeinstaller.job
2013-09-28 22:31 - 2013-09-28 22:33 - 00000000 ____D C:\Program Files (x86)\Feven 1.5
2013-09-28 22:30 - 2013-09-28 22:30 - 00236248 _____ (Tuguu S.L.U) C:\Users\Wild-Pako\Downloads\cpu-z.exe
2013-09-28 22:12 - 2013-09-28 22:12 - 00000000 ____D C:\Program Files\Defraggler
2013-09-28 22:11 - 2013-09-28 22:11 - 03084304 _____ (Piriform Ltd) C:\Users\Wild-Pako\Downloads\dfsetup215742_slim.exe
2013-09-28 22:11 - 2013-09-28 22:11 - 03084304 _____ (Piriform Ltd) C:\Users\Wild-Pako\Downloads\dfsetup215742_slim (1).exe
2013-09-28 22:07 - 2013-09-28 22:07 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\avgchrome
2013-09-28 21:41 - 2013-09-28 21:41 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\2K Games
2013-09-28 21:39 - 2013-09-28 21:39 - 00000902 _____ C:\Users\Wild-Pako\Desktop\SteamLess Mafia II.lnk
2013-09-28 21:39 - 2013-09-28 21:39 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steamless Mafia II Pack
2013-09-28 18:04 - 2013-10-09 18:26 - 01593956 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-09-28 13:51 - 2013-09-28 13:51 - 00001964 _____ C:\Users\Public\Desktop\FileZilla Client.lnk
2013-09-28 13:51 - 2013-09-28 13:51 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2013-09-27 23:09 - 2013-09-27 23:09 - 00000000 ____D C:\Users\Wild-Pako\Documents\Rockstar Games
2013-09-27 23:05 - 2013-09-27 23:05 - 00000000 __SHD C:\ProgramData\SecuROM
2013-09-27 23:05 - 2013-09-27 23:05 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Rockstar Games
2013-09-27 22:54 - 2013-09-27 22:54 - 00000000 ____D C:\Windows\SysWOW64\xlive
2013-09-27 22:54 - 2013-09-27 22:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2013-09-27 22:53 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
2013-09-27 22:53 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2013-09-27 22:53 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
2013-09-27 22:53 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2013-09-27 22:53 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2013-09-27 22:53 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2013-09-27 22:53 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2013-09-27 22:53 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2013-09-27 22:53 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2013-09-27 22:53 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2013-09-27 22:53 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2013-09-27 22:53 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2013-09-27 22:53 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2013-09-27 22:53 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
2013-09-27 22:53 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2013-09-27 22:53 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
2013-09-27 22:53 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2013-09-27 22:53 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2013-09-27 22:53 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2013-09-27 22:53 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
2013-09-27 22:53 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2013-09-27 22:53 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2013-09-27 22:53 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2013-09-27 22:53 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2013-09-27 22:53 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2013-09-27 22:53 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2013-09-27 22:53 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2013-09-27 22:53 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2013-09-27 22:53 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2013-09-27 22:53 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2013-09-27 22:53 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
2013-09-27 22:53 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
2013-09-27 22:53 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2013-09-27 22:53 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2013-09-27 22:53 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
2013-09-27 22:53 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2013-09-27 22:53 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
2013-09-27 22:53 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2013-09-27 22:53 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll
2013-09-27 22:53 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2013-09-27 22:53 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll
2013-09-27 22:53 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2013-09-27 22:53 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
2013-09-27 22:53 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2013-09-27 22:53 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2013-09-27 22:53 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2013-09-27 22:53 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
2013-09-27 22:53 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2013-09-27 22:53 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
2013-09-27 22:53 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2013-09-27 22:53 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2013-09-27 22:53 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2013-09-27 22:53 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2013-09-27 22:53 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2013-09-27 22:53 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2013-09-27 22:53 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2013-09-27 22:53 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2013-09-27 22:53 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2013-09-27 22:53 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
2013-09-27 22:53 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2013-09-27 22:53 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
2013-09-27 22:53 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2013-09-27 22:53 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2013-09-27 22:53 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2013-09-27 22:53 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2013-09-27 22:53 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2013-09-27 22:53 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2013-09-27 22:53 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2013-09-27 22:53 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
2013-09-27 22:53 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
2013-09-27 22:53 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2013-09-27 22:53 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2013-09-27 22:53 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
2013-09-27 22:53 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
2013-09-27 22:53 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2013-09-27 22:53 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2013-09-27 22:53 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2013-09-27 22:53 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2013-09-27 22:53 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
2013-09-27 22:53 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2013-09-27 22:53 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
2013-09-27 22:53 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2013-09-27 22:53 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
2013-09-27 22:53 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
2013-09-27 22:53 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2013-09-27 22:53 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2013-09-27 22:53 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
2013-09-27 22:53 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2013-09-27 22:53 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
2013-09-27 22:53 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2013-09-27 22:53 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
2013-09-27 22:53 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2013-09-27 22:53 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
2013-09-27 22:53 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2013-09-27 22:53 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
2013-09-27 22:53 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2013-09-27 22:53 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
2013-09-27 22:53 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2013-09-27 22:53 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
2013-09-27 22:53 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2013-09-27 22:53 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
2013-09-27 22:53 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2013-09-27 22:53 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
2013-09-27 22:53 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2013-09-27 22:53 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
2013-09-27 22:53 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2013-09-27 22:53 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2013-09-27 22:53 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2013-09-27 22:53 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
2013-09-27 22:53 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2013-09-27 22:53 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
2013-09-27 22:53 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2013-09-27 22:53 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
2013-09-27 22:53 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2013-09-27 22:53 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2013-09-27 22:53 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2013-09-27 22:53 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
2013-09-27 22:53 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2013-09-27 22:53 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
2013-09-27 22:53 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2013-09-27 22:53 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
2013-09-27 22:53 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2013-09-27 22:53 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2013-09-27 22:53 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2013-09-27 22:53 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2013-09-27 22:53 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2013-09-27 22:53 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2013-09-27 22:53 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2013-09-27 22:53 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2013-09-27 22:53 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2013-09-27 22:53 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
2013-09-27 22:53 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2013-09-27 22:53 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2013-09-27 22:53 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2013-09-27 22:53 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2013-09-27 22:52 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2013-09-27 22:52 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2013-09-27 22:52 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2013-09-27 22:52 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2013-09-27 22:52 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2013-09-27 22:52 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2013-09-27 22:52 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2013-09-27 22:52 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2013-09-27 22:52 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2013-09-27 22:52 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2013-09-27 22:52 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2013-09-27 22:52 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2013-09-27 22:52 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2013-09-27 22:52 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2013-09-27 22:52 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2013-09-27 22:52 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2013-09-27 22:52 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2013-09-27 22:52 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2013-09-27 22:52 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2013-09-27 22:52 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2013-09-27 22:52 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2013-09-27 22:52 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2013-09-27 22:52 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2013-09-27 22:52 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2013-09-27 22:52 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2013-09-27 22:52 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2013-09-27 22:52 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2013-09-27 22:52 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2013-09-27 22:52 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2013-09-27 22:52 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2013-09-27 22:52 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2013-09-27 22:52 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2013-09-27 22:51 - 2013-09-27 22:51 - 00001045 _____ C:\Users\Public\Desktop\Grand Theft Auto IV Complete Edition.lnk
2013-09-27 17:14 - 2013-09-27 17:18 - 00000000 ____D C:\tempvideo
2013-09-27 17:13 - 2013-09-27 23:05 - 00000044 _____ C:\DebugTraceAP.log
2013-09-27 12:43 - 2013-09-27 12:45 - 00000000 ____D C:\Program Files (x86)\DU Meter
2013-09-27 12:43 - 2013-09-27 12:43 - 00000000 ____D C:\ProgramData\Hagel Technologies
2013-09-27 12:23 - 2013-09-27 12:23 - 00001047 _____ C:\Users\Wild-Pako\Desktop\Dropbox.lnk
2013-09-27 12:21 - 2013-09-27 12:21 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-09-27 12:20 - 2013-10-12 19:52 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Dropbox
2013-09-27 11:48 - 2013-09-27 11:48 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Miranda IM
2013-09-27 08:22 - 2013-09-27 08:22 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\OpenOffice
2013-09-27 08:19 - 2013-09-27 08:19 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk
2013-09-27 08:18 - 2013-09-27 08:19 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-09-26 20:17 - 2013-10-03 04:52 - 00001050 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk
2013-09-26 20:17 - 2013-09-26 20:17 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2013-09-26 15:00 - 2013-09-26 15:00 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-09-26 15:00 - 2013-09-26 15:00 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-09-26 07:52 - 2013-10-12 19:50 - 00004173 _____ C:\Windows\setupact.log
2013-09-26 07:52 - 2013-09-26 07:52 - 00000000 _____ C:\Windows\setuperr.log
2013-09-25 22:15 - 2013-09-25 22:15 - 00000783 _____ C:\Users\Wild-Pako\Desktop\! - - Transfer - - !.lnk
2013-09-25 21:57 - 2013-09-25 21:57 - 00000000 ____D C:\ProgramData\Canneverbe Limited
2013-09-25 21:56 - 2013-09-25 21:56 - 00001913 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk
2013-09-25 21:56 - 2013-09-25 21:56 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Canneverbe Limited
2013-09-25 21:56 - 2013-09-25 21:56 - 00000000 ____D C:\Program Files (x86)\CDBurnerXP
2013-09-25 21:51 - 2013-09-25 21:51 - 00001501 _____ C:\Users\Wild-Pako\Desktop\Load.lnk
2013-09-25 21:34 - 2013-09-25 21:34 - 00001282 _____ C:\Users\Public\Desktop\EL3K My ELAS Remote Programmer.lnk
2013-09-25 21:34 - 2013-09-25 21:34 - 00000000 ____D C:\Program Files (x86)\Electronics Line
2013-09-25 20:41 - 2013-09-25 20:41 - 00002050 _____ C:\Users\Wild-Pako\Desktop\JDownloader.lnk
2013-09-25 20:40 - 2013-09-25 20:40 - 00000000 ____D C:\Users\Wild-Pako\Programme
2013-09-25 20:29 - 2013-09-25 20:31 - 00000000 ____D C:\Windows\rescache
2013-09-25 19:58 - 2013-09-25 19:59 - 175636928 _____ C:\Users\Wild-Pako\Downloads\130254498000.rar.part
2013-09-25 19:40 - 2013-10-12 19:53 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-25 19:40 - 2013-10-10 18:48 - 00004112 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-09-25 19:40 - 2013-10-10 18:48 - 00003860 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-09-25 19:40 - 2013-10-08 00:48 - 00002143 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-09-25 19:39 - 2013-10-12 19:51 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-25 19:39 - 2013-10-04 22:11 - 00001702 _____ C:\Users\Wild-Pako\Desktop\MPC-HC x64.lnk
2013-09-25 19:39 - 2013-10-04 22:11 - 00000000 ____D C:\Program Files\MPC-HC
2013-09-25 19:39 - 2013-09-25 19:40 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Google
2013-09-25 19:39 - 2013-09-25 19:40 - 00000000 ____D C:\Program Files (x86)\Google
2013-09-25 19:39 - 2013-09-25 19:39 - 00784872 _____ (Google Inc.) C:\Users\Wild-Pako\Downloads\ChromeSetup.exe
2013-09-25 19:38 - 2013-09-25 19:38 - 07990240 _____ (MPC-HC Team                                                 ) C:\Users\Wild-Pako\Downloads\MPC-HC.1.6.8.x64.exe
2013-09-25 19:38 - 2013-09-25 19:38 - 00001030 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-09-25 19:37 - 2013-09-25 19:37 - 23003252 _____ C:\Users\Wild-Pako\Downloads\vlc-2.0.8-win32.exe
2013-09-25 19:07 - 2013-10-09 18:23 - 00000000 ____D C:\Windows\system32\MRT
2013-09-25 18:00 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-09-25 18:00 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-09-25 18:00 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-09-25 18:00 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-09-25 18:00 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-09-25 18:00 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-09-25 18:00 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-09-25 18:00 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-09-25 18:00 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-09-25 18:00 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-09-25 18:00 - 2013-04-12 16:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2013-09-25 18:00 - 2013-04-10 08:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2013-09-25 18:00 - 2011-02-03 13:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2013-09-25 17:59 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-09-25 17:59 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-09-25 17:59 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-09-25 17:59 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-09-25 17:59 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-09-25 17:59 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-25 17:59 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-09-25 17:59 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-25 17:59 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-09-25 17:59 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-09-25 17:59 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-09-25 17:59 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-09-25 17:59 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-09-25 17:59 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-25 17:59 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-09-25 17:59 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-09-25 17:59 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-09-25 17:59 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-09-25 17:59 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-09-25 17:59 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-09-25 17:43 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-25 17:43 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-25 17:43 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-25 17:43 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-09-25 17:43 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-09-25 17:43 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-09-25 17:43 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-09-25 17:43 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-09-25 17:43 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-09-25 17:43 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-09-25 17:43 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-09-25 17:43 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-09-25 17:43 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-09-25 17:43 - 2013-05-13 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2013-09-25 17:43 - 2013-05-13 05:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2013-09-25 17:43 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-09-25 17:43 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-09-25 17:43 - 2013-05-10 07:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2013-09-25 17:43 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-09-25 17:43 - 2013-04-26 07:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-09-25 17:43 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-09-25 17:43 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-09-25 17:43 - 2013-04-17 09:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-09-25 17:43 - 2013-04-17 08:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2013-09-25 17:43 - 2013-04-01 00:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2013-09-25 17:43 - 2013-03-19 07:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2013-09-25 17:43 - 2013-03-19 07:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2013-09-25 17:43 - 2013-02-27 08:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2013-09-25 17:43 - 2013-02-27 07:48 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-09-25 17:43 - 2013-02-27 07:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2013-09-25 17:43 - 2013-02-27 06:49 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-09-25 17:38 - 2013-09-25 17:38 - 00000000 ____D C:\ProgramData\Oracle
2013-09-25 17:38 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-09-25 17:38 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-09-25 17:37 - 2013-09-25 17:36 - 00868264 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-09-25 17:37 - 2013-09-25 17:36 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-09-25 17:37 - 2013-09-25 17:36 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-09-25 17:37 - 2013-09-25 17:36 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-09-25 17:37 - 2013-09-25 17:36 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-09-25 17:20 - 2013-09-25 17:20 - 02564703 _____ C:\Users\Wild-Pako\Downloads\CMI8738_WDM_0639XP.zip
2013-09-25 17:02 - 2012-07-26 06:55 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2013-09-25 17:02 - 2012-07-26 04:36 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2013-09-25 17:02 - 2012-06-02 16:35 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2013-09-25 16:56 - 2013-09-25 16:56 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-09-25 16:56 - 2013-09-25 16:56 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-09-25 16:56 - 2013-09-25 16:56 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-09-25 16:56 - 2013-09-25 16:56 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-09-25 16:56 - 2013-09-25 16:56 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-09-25 16:56 - 2013-09-25 16:56 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-09-25 16:56 - 2013-09-25 16:56 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-09-25 16:56 - 2013-09-25 16:56 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-09-25 16:56 - 2013-09-25 16:56 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-09-25 16:55 - 2013-09-25 17:02 - 00008799 _____ C:\Windows\IE10_main.log
2013-09-25 16:54 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2013-09-25 16:54 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2013-09-25 16:54 - 2012-08-23 16:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2013-09-25 16:54 - 2012-08-23 15:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2013-09-25 16:54 - 2012-08-23 15:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2013-09-25 16:54 - 2012-08-23 15:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-09-25 16:54 - 2012-08-23 15:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-09-25 16:54 - 2012-08-23 15:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2013-09-25 16:54 - 2012-08-23 15:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2013-09-25 16:54 - 2012-08-23 15:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-09-25 16:54 - 2012-08-23 15:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2013-09-25 16:54 - 2012-08-23 15:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-09-25 16:54 - 2012-08-23 14:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2013-09-25 16:54 - 2012-08-23 13:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2013-09-25 16:54 - 2012-08-23 13:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-09-25 16:54 - 2012-08-23 13:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2013-09-25 16:54 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2013-09-25 16:54 - 2012-08-23 12:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2013-09-25 16:54 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2013-09-25 16:54 - 2012-08-23 12:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2013-09-25 16:54 - 2012-08-23 12:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2013-09-25 16:54 - 2012-08-23 11:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2013-09-25 16:54 - 2012-08-23 10:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-09-25 16:54 - 2012-08-23 10:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2013-09-25 16:51 - 2012-07-26 05:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2013-09-25 16:51 - 2012-07-26 05:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2013-09-25 16:51 - 2012-07-26 05:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2013-09-25 16:51 - 2012-07-26 05:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2013-09-25 16:51 - 2012-07-26 05:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2013-09-25 16:51 - 2012-07-26 04:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2013-09-25 16:51 - 2012-07-26 04:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2013-09-25 16:51 - 2012-06-02 16:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2013-09-25 16:48 - 2013-01-13 23:17 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 23:17 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 23:16 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 23:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-09-25 16:48 - 2013-01-13 23:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-09-25 16:48 - 2013-01-13 23:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 23:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 23:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 23:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:35 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:35 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:35 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:22 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-09-25 16:48 - 2013-01-13 22:20 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2013-09-25 16:48 - 2013-01-13 22:09 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2013-09-25 16:48 - 2013-01-13 22:08 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2013-09-25 16:48 - 2013-01-13 21:58 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-09-25 16:48 - 2013-01-13 21:54 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-09-25 16:48 - 2013-01-13 21:53 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2013-09-25 16:48 - 2013-01-13 21:53 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2013-09-25 16:48 - 2013-01-13 21:51 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-09-25 16:48 - 2013-01-13 21:49 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2013-09-25 16:48 - 2013-01-13 21:48 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2013-09-25 16:48 - 2013-01-13 21:46 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2013-09-25 16:48 - 2013-01-13 21:38 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-09-25 16:48 - 2013-01-13 21:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-09-25 16:48 - 2013-01-13 21:37 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-09-25 16:48 - 2013-01-13 21:25 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2013-09-25 16:48 - 2013-01-13 21:24 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-09-25 16:48 - 2013-01-13 21:24 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2013-09-25 16:48 - 2013-01-13 21:20 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-09-25 16:48 - 2013-01-13 21:20 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-09-25 16:48 - 2013-01-13 21:10 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-09-25 16:48 - 2013-01-13 21:02 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-09-25 16:48 - 2013-01-13 20:34 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-09-25 16:48 - 2013-01-13 20:32 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-09-25 16:48 - 2013-01-13 20:09 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-09-25 16:48 - 2013-01-13 19:26 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2013-09-25 16:48 - 2013-01-13 19:05 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2013-09-25 16:48 - 2013-01-04 08:11 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2013-09-25 16:48 - 2013-01-04 08:11 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2013-09-25 16:46 - 2013-01-24 08:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2013-09-25 16:46 - 2012-12-07 15:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2013-09-25 16:46 - 2012-12-07 15:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2013-09-25 16:46 - 2012-12-07 14:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2013-09-25 16:46 - 2012-12-07 14:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2013-09-25 16:46 - 2012-12-07 13:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2013-09-25 16:46 - 2012-12-07 13:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2013-09-25 16:46 - 2012-12-07 13:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2013-09-25 16:46 - 2012-12-07 13:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2013-09-25 16:46 - 2012-12-07 13:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2013-09-25 16:46 - 2012-12-07 13:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2013-09-25 16:46 - 2012-12-07 13:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2013-09-25 16:46 - 2012-12-07 13:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2013-09-25 16:46 - 2012-12-07 13:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2013-09-25 16:46 - 2012-12-07 13:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2013-09-25 16:46 - 2012-12-07 13:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2013-09-25 16:46 - 2012-12-07 13:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2013-09-25 16:46 - 2012-12-07 13:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2013-09-25 16:46 - 2012-12-07 13:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs
2013-09-25 16:46 - 2012-11-30 01:17 - 00420064 _____ C:\Windows\SysWOW64\locale.nls
2013-09-25 16:46 - 2012-11-30 01:15 - 00420064 _____ C:\Windows\system32\locale.nls
2013-09-25 16:46 - 2012-11-22 07:44 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2013-09-25 16:46 - 2012-11-22 06:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2013-09-25 16:46 - 2012-10-09 20:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2013-09-25 16:46 - 2012-10-09 20:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2013-09-25 16:46 - 2012-10-09 19:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2013-09-25 16:46 - 2012-10-09 19:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2013-09-25 16:46 - 2012-10-03 19:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2013-09-25 16:46 - 2012-10-03 19:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2013-09-25 16:46 - 2012-10-03 19:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2013-09-25 16:46 - 2012-10-03 19:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2013-09-25 16:46 - 2012-10-03 19:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2013-09-25 16:46 - 2012-10-03 19:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2013-09-25 16:46 - 2012-10-03 18:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
2013-09-25 16:46 - 2012-10-03 18:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2013-09-25 16:46 - 2012-10-03 18:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
2013-09-25 16:46 - 2012-10-03 18:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2013-09-25 16:46 - 2012-08-24 20:13 - 00154480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-09-25 16:46 - 2012-08-24 20:09 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-09-25 16:46 - 2012-08-24 20:05 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-09-25 16:46 - 2012-08-24 20:03 - 01448448 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-09-25 16:46 - 2012-08-24 18:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-09-25 16:46 - 2012-08-24 18:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-09-25 16:46 - 2012-08-24 18:53 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-09-25 16:46 - 2012-08-22 20:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2013-09-25 16:46 - 2012-08-21 23:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
2013-09-25 16:46 - 2012-07-04 22:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
2013-09-25 16:46 - 2012-05-05 10:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2013-09-25 16:46 - 2012-05-05 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2013-09-25 16:46 - 2012-05-04 13:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2013-09-25 16:46 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2013-09-25 16:46 - 2012-01-13 09:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2013-09-25 16:42 - 2012-02-11 08:36 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2013-09-25 16:42 - 2012-02-11 08:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
2013-09-25 16:42 - 2011-05-04 07:25 - 02315776 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2013-09-25 16:42 - 2011-05-04 07:22 - 02223616 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2013-09-25 16:42 - 2011-05-04 07:22 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2013-09-25 16:42 - 2011-05-04 07:22 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2013-09-25 16:42 - 2011-05-04 07:22 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2013-09-25 16:42 - 2011-05-04 07:22 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2013-09-25 16:42 - 2011-05-04 07:19 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2013-09-25 16:42 - 2011-05-04 07:19 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2013-09-25 16:42 - 2011-05-04 07:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2013-09-25 16:42 - 2011-05-04 06:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2013-09-25 16:42 - 2011-05-04 06:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2013-09-25 16:42 - 2011-05-04 06:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2013-09-25 16:42 - 2011-05-04 06:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2013-09-25 16:42 - 2011-05-04 06:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2013-09-25 16:42 - 2011-05-04 06:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2013-09-25 16:42 - 2011-05-04 06:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2013-09-25 16:42 - 2011-05-04 06:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2013-09-25 16:42 - 2011-05-04 06:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2013-09-25 16:39 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2013-09-25 16:39 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2013-09-25 16:38 - 2013-09-25 16:38 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in
2013-09-25 16:38 - 2013-09-25 16:38 - 00000000 ____D C:\Program Files (x86)\Winamp Detect
2013-09-25 16:37 - 2013-09-25 16:37 - 13385888 _____ (Nullsoft, Inc.) C:\Users\Wild-Pako\Downloads\winamp565_full_emusic-7plus_de-de.exe
2013-09-24 19:15 - 2013-09-25 16:39 - 00000943 _____ C:\Users\Public\Desktop\Winamp.lnk
2013-09-24 19:14 - 2013-09-25 17:22 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Winamp
2013-09-24 19:14 - 2013-09-25 16:39 - 00000000 ____D C:\Program Files (x86)\Winamp
2013-09-24 19:14 - 2011-03-04 21:44 - 02095600 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxsfs.dll
2013-09-24 19:14 - 2011-03-04 21:44 - 00698864 ____N (Sonic Solutions) C:\Windows\SysWOW64\px.dll
2013-09-24 19:14 - 2011-03-04 21:44 - 00571888 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxdrv.dll
2013-09-24 19:14 - 2011-03-04 21:44 - 00440816 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxwave.dll
2013-09-24 19:14 - 2011-03-04 21:44 - 00219632 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxmas.dll
2013-09-24 19:14 - 2011-03-04 21:44 - 00133616 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxafs.dll
2013-09-24 19:14 - 2011-03-04 21:44 - 00100848 ____N (Sonic Solutions) C:\Windows\SysWOW64\vxblock.dll
2013-09-24 19:14 - 2011-03-04 21:44 - 00072176 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxhpinst.exe
2013-09-24 19:14 - 2011-03-04 21:44 - 00068592 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxinsa64.exe
2013-09-24 19:14 - 2011-03-04 21:44 - 00068080 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxcpya64.exe
2013-09-22 18:16 - 2013-09-27 08:11 - 00000000 ____D C:\Windows\system32\appmgmt
2013-09-22 18:11 - 2013-09-22 18:11 - 00003196 _____ C:\Windows\System32\Tasks\{758CECE7-FCF0-43F8-9FAD-6E45BC86DE8D}
2013-09-20 19:52 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2013-09-20 19:52 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2013-09-20 19:49 - 2013-09-20 19:54 - 00466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2013-09-20 19:49 - 2013-09-20 19:54 - 00444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2013-09-20 19:49 - 2013-09-20 19:54 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2013-09-20 19:49 - 2013-09-20 19:54 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2013-09-20 19:49 - 2013-09-20 19:54 - 00000628 _____ C:\Users\Public\Desktop\3DMark06.lnk
2013-09-20 19:49 - 2013-09-20 19:49 - 00000000 ____D C:\Program Files (x86)\OpenAL
2013-09-20 19:47 - 2013-09-20 19:47 - 00000000 ____D C:\Program Files (x86)\Futuremark
2013-09-20 19:44 - 2013-09-20 19:44 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\ATI
2013-09-20 19:44 - 2013-09-20 19:44 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\ATI
2013-09-20 19:43 - 2013-09-20 19:43 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2013-09-18 19:40 - 2013-09-18 19:40 - 00000000 _____ C:\Windows\ativpsrm.bin
2013-09-18 19:39 - 2013-09-18 19:39 - 00000000 ____D C:\Program Files (x86)\AMD APP
2013-09-18 19:38 - 2013-10-07 18:57 - 00000000 ____D C:\Program Files\ATI Technologies
2013-09-18 19:38 - 2013-09-18 19:38 - 00000000 ____D C:\Program Files\ATI

==================== One Month Modified Files and Folders =======

2013-10-12 20:10 - 2013-10-12 20:10 - 00000000 ____D C:\FRST
2013-10-12 20:09 - 2013-10-12 20:09 - 00000168 _____ C:\Users\Wild-Pako\defogger_reenable
2013-10-12 20:09 - 2009-08-13 17:20 - 00000000 ____D C:\Users\Wild-Pako
2013-10-12 19:56 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-12 19:56 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-12 19:54 - 2009-08-13 17:15 - 01258373 _____ C:\Windows\WindowsUpdate.log
2013-10-12 19:53 - 2013-09-25 19:40 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-12 19:52 - 2013-10-08 19:58 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-10-12 19:52 - 2013-09-27 12:20 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Dropbox
2013-10-12 19:51 - 2013-09-28 22:33 - 00001286 _____ C:\Windows\Tasks\Feven 1.5-updater.job
2013-10-12 19:51 - 2013-09-28 22:33 - 00001190 _____ C:\Windows\Tasks\Feven 1.5-codedownloader.job
2013-10-12 19:51 - 2013-09-28 22:33 - 00001090 _____ C:\Windows\Tasks\Feven 1.5-enabler.job
2013-10-12 19:51 - 2013-09-28 22:32 - 00001818 _____ C:\Windows\Tasks\Feven 1.5-firefoxinstaller.job
2013-10-12 19:51 - 2013-09-28 22:31 - 00001894 _____ C:\Windows\Tasks\Feven 1.5-chromeinstaller.job
2013-10-12 19:51 - 2013-09-25 19:39 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-12 19:51 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-12 19:50 - 2013-09-26 07:52 - 00004173 _____ C:\Windows\setupact.log
2013-10-12 19:49 - 2013-10-12 19:48 - 00000000 ____D C:\AdwCleaner
2013-10-12 19:38 - 2012-07-31 20:20 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-12 17:57 - 2009-08-13 18:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-10-12 17:16 - 2009-08-13 22:16 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Thunderbird
2013-10-12 17:08 - 2013-10-12 17:08 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\SCE
2013-10-12 17:07 - 2013-10-12 17:07 - 00000810 _____ C:\Users\Wild-Pako\Desktop\PlanetSide 2 PSG.lnk
2013-10-12 17:07 - 2013-10-12 17:07 - 00000810 _____ C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlanetSide 2 PSG.lnk
2013-10-11 19:53 - 2013-09-29 14:07 - 00000000 ____D C:\Windows\Minidump
2013-10-11 15:14 - 2009-08-13 22:36 - 00196378 _____ C:\Windows\PFRO.log
2013-10-10 19:08 - 2013-10-02 21:06 - 00000000 ____D C:\Users\Wild-Pako\Documents\Criterion Games
2013-10-10 19:02 - 2013-10-10 19:02 - 00001084 _____ C:\Users\Public\Desktop\Need for Speed Most Wanted.lnk
2013-10-10 18:48 - 2013-09-25 19:40 - 00004112 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-10 18:48 - 2013-09-25 19:40 - 00003860 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-10 18:45 - 2009-08-13 17:20 - 00000000 ___RD C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-09 21:54 - 2013-10-09 21:53 - 00000000 ____D C:\Users\Wild-Pako\Documents\NFSTR
2013-10-09 18:38 - 2012-07-31 20:20 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-09 18:38 - 2012-07-31 20:20 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-09 18:38 - 2012-07-31 20:20 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-09 18:31 - 2009-07-14 06:45 - 00295824 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-09 18:26 - 2013-09-28 18:04 - 01593956 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-10-09 18:26 - 2009-07-26 14:25 - 00699416 _____ C:\Windows\system32\perfh007.dat
2013-10-09 18:26 - 2009-07-26 14:25 - 00149556 _____ C:\Windows\system32\perfc007.dat
2013-10-09 18:26 - 2009-07-14 07:13 - 01593956 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-09 18:23 - 2013-09-25 19:07 - 00000000 ____D C:\Windows\system32\MRT
2013-10-09 18:22 - 2010-10-02 14:30 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-08 21:32 - 2013-10-08 21:32 - 00001374 _____ C:\Users\Wild-Pako\Desktop\farcry3.lnk
2013-10-08 21:32 - 2013-10-08 21:32 - 00000000 ____D C:\Users\Wild-Pako\Documents\My Games
2013-10-08 21:32 - 2013-10-08 21:32 - 00000000 ____D C:\ProgramData\Orbit
2013-10-08 21:20 - 2012-11-04 16:24 - 00328221 _____ C:\Windows\DirectX.log
2013-10-08 21:03 - 2009-08-13 17:34 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-08 20:39 - 2013-10-08 20:39 - 00001513 _____ C:\Users\Wild-Pako\Desktop\Need For Speed The Run.lnk
2013-10-08 19:58 - 2013-10-08 19:58 - 00001922 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-10-08 19:58 - 2009-08-13 20:26 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-10-08 19:56 - 2013-10-08 19:56 - 00000000 ____D C:\Program Files\AVAST Software
2013-10-08 19:56 - 2013-10-08 19:52 - 00000000 ____D C:\ProgramData\AVAST Software
2013-10-08 19:08 - 2013-10-08 19:08 - 00000000 ____D C:\ProgramData\Futuremark
2013-10-08 19:07 - 2013-10-08 19:07 - 00000924 _____ C:\Users\Public\Desktop\3DMark Vantage.lnk
2013-10-08 19:06 - 2013-10-08 19:06 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-10-08 19:06 - 2013-10-08 19:06 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-10-08 00:48 - 2013-09-25 19:40 - 00002143 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-10-07 22:10 - 2013-10-01 12:42 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\CrossLoop
2013-10-07 22:09 - 2013-10-07 21:59 - 00001760 _____ C:\Windows\wininit.ini
2013-10-07 21:59 - 2013-10-07 21:38 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-10-07 21:57 - 2013-10-07 21:57 - 00007601 _____ C:\Users\Wild-Pako\AppData\Local\Resmon.ResmonCfg
2013-10-07 21:39 - 2013-10-07 21:38 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-10-07 21:38 - 2013-10-07 21:38 - 00001343 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-10-07 21:38 - 2013-10-07 21:38 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-10-07 19:10 - 2013-10-07 19:10 - 00000000 ____D C:\ProgramData\ATI
2013-10-07 18:58 - 2013-10-07 18:58 - 00055617 _____ C:\Windows\SysWOW64\CCCInstall_201310071858030463.log
2013-10-07 18:58 - 2013-10-07 18:58 - 00000000 ____D C:\ProgramData\AMD
2013-10-07 18:58 - 2013-10-07 18:58 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2013-10-07 18:57 - 2013-09-18 19:38 - 00000000 ____D C:\Program Files\ATI Technologies
2013-10-07 18:56 - 2013-10-07 18:56 - 00018620 _____ C:\Windows\SysWOW64\CCCInstall_201310071856358562.log
2013-10-07 18:55 - 2013-10-07 18:55 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2013-10-07 18:53 - 2013-10-07 18:52 - 00000000 ____D C:\ProgramData\Package Cache
2013-10-06 23:20 - 2013-10-06 23:20 - 00000045 _____ C:\Users\Wild-Pako\Desktop\Neues Textdokument.txt
2013-10-05 17:01 - 2009-08-14 12:09 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\vlc
2013-10-04 22:11 - 2013-09-25 19:39 - 00001702 _____ C:\Users\Wild-Pako\Desktop\MPC-HC x64.lnk
2013-10-04 22:11 - 2013-09-25 19:39 - 00000000 ____D C:\Program Files\MPC-HC
2013-10-03 18:26 - 2013-10-03 18:20 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
2013-10-03 14:47 - 2013-10-03 13:51 - 00037130 _____ C:\pingstat.txt
2013-10-03 13:50 - 2013-10-03 13:49 - 00000332 _____ C:\Users\Wild-Pako\Desktop\Neues Textdokument.bat
2013-10-03 10:26 - 2013-10-03 10:26 - 00001160 _____ C:\Users\Wild-Pako\Desktop\launcher - Verknüpfung.lnk
2013-10-03 10:25 - 2013-09-29 11:35 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhoenixRC
2013-10-03 10:23 - 2013-09-29 11:39 - 00000000 ____D C:\Users\Wild-Pako\Documents\PhoenixRC
2013-10-03 04:52 - 2013-09-26 20:17 - 00001050 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk
2013-10-02 23:03 - 2013-10-02 23:03 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Sinvise Systems
2013-10-02 23:03 - 2013-10-02 23:03 - 00000000 ____D C:\Program Files (x86)\Sinvise Systems
2013-10-02 21:27 - 2013-10-02 21:26 - 00000000 ____D C:\Users\Wild-Pako\Documents\NFS Undercover
2013-10-02 21:24 - 2013-10-02 21:24 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Leadertech
2013-10-02 21:06 - 2013-10-02 21:06 - 00000000 ____D C:\ProgramData\Electronic Arts
2013-10-02 21:06 - 2013-10-02 21:06 - 00000000 ____D C:\ProgramData\EA Core
2013-10-02 19:29 - 2009-08-14 12:09 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\dvdcss
2013-09-29 13:48 - 2013-09-29 13:45 - 00000000 ____D C:\Users\Wild-Pako\Desktop\Prime95
2013-09-29 13:43 - 2013-09-29 13:43 - 00000948 _____ C:\Users\Wild-Pako\Desktop\Core Temp.lnk
2013-09-29 12:29 - 2012-11-07 23:30 - 00000647 _____ C:\Users\Public\Desktop\HELI-X4.lnk
2013-09-29 11:43 - 2013-09-29 11:43 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-09-28 22:33 - 2013-09-28 22:33 - 00004316 _____ C:\Windows\System32\Tasks\Feven 1.5-updater
2013-09-28 22:33 - 2013-09-28 22:33 - 00004220 _____ C:\Windows\System32\Tasks\Feven 1.5-codedownloader
2013-09-28 22:33 - 2013-09-28 22:33 - 00004120 _____ C:\Windows\System32\Tasks\Feven 1.5-enabler
2013-09-28 22:33 - 2013-09-28 22:31 - 00000000 ____D C:\Program Files (x86)\Feven 1.5
2013-09-28 22:32 - 2013-09-28 22:32 - 00000869 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2013-09-28 22:32 - 2013-09-28 22:32 - 00000000 ____D C:\Program Files\CPUID
2013-09-28 22:30 - 2013-09-28 22:30 - 00236248 _____ (Tuguu S.L.U) C:\Users\Wild-Pako\Downloads\cpu-z.exe
2013-09-28 22:12 - 2013-09-28 22:12 - 00000000 ____D C:\Program Files\Defraggler
2013-09-28 22:11 - 2013-09-28 22:11 - 03084304 _____ (Piriform Ltd) C:\Users\Wild-Pako\Downloads\dfsetup215742_slim.exe
2013-09-28 22:11 - 2013-09-28 22:11 - 03084304 _____ (Piriform Ltd) C:\Users\Wild-Pako\Downloads\dfsetup215742_slim (1).exe
2013-09-28 22:07 - 2013-09-28 22:07 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\avgchrome
2013-09-28 22:03 - 2010-04-09 20:01 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-09-28 22:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Help
2013-09-28 21:41 - 2013-09-28 21:41 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\2K Games
2013-09-28 21:39 - 2013-09-28 21:39 - 00000902 _____ C:\Users\Wild-Pako\Desktop\SteamLess Mafia II.lnk
2013-09-28 21:39 - 2013-09-28 21:39 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steamless Mafia II Pack
2013-09-28 20:02 - 2010-08-07 22:58 - 00043520 _____ C:\Windows\SysWOW64\CmdLineExt03.dll
2013-09-28 13:59 - 2012-11-10 19:12 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\FileZilla
2013-09-28 13:51 - 2013-09-28 13:51 - 00001964 _____ C:\Users\Public\Desktop\FileZilla Client.lnk
2013-09-28 13:51 - 2013-09-28 13:51 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2013-09-28 11:22 - 2012-07-25 18:41 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-27 23:09 - 2013-09-27 23:09 - 00000000 ____D C:\Users\Wild-Pako\Documents\Rockstar Games
2013-09-27 23:05 - 2013-09-27 23:05 - 00000000 __SHD C:\ProgramData\SecuROM
2013-09-27 23:05 - 2013-09-27 23:05 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Rockstar Games
2013-09-27 23:05 - 2013-09-27 17:13 - 00000044 _____ C:\DebugTraceAP.log
2013-09-27 22:54 - 2013-09-27 22:54 - 00000000 ____D C:\Windows\SysWOW64\xlive
2013-09-27 22:54 - 2013-09-27 22:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2013-09-27 22:54 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-09-27 22:51 - 2013-09-27 22:51 - 00001045 _____ C:\Users\Public\Desktop\Grand Theft Auto IV Complete Edition.lnk
2013-09-27 17:18 - 2013-09-27 17:14 - 00000000 ____D C:\tempvideo
2013-09-27 12:45 - 2013-09-27 12:43 - 00000000 ____D C:\Program Files (x86)\DU Meter
2013-09-27 12:43 - 2013-09-27 12:43 - 00000000 ____D C:\ProgramData\Hagel Technologies
2013-09-27 12:23 - 2013-09-27 12:23 - 00001047 _____ C:\Users\Wild-Pako\Desktop\Dropbox.lnk
2013-09-27 12:21 - 2013-09-27 12:21 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-09-27 11:48 - 2013-09-27 11:48 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Miranda IM
2013-09-27 11:48 - 2009-08-13 18:07 - 00000990 _____ C:\Users\Wild-Pako\Desktop\Miranda IM.lnk
2013-09-27 11:48 - 2009-08-13 18:07 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Miranda
2013-09-27 11:48 - 2009-08-13 18:07 - 00000000 ____D C:\Program Files (x86)\Miranda IM
2013-09-27 09:04 - 2009-08-13 22:16 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Thunderbird
2013-09-27 09:04 - 2009-08-13 18:06 - 00002050 _____ C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2013-09-27 08:51 - 2009-08-13 17:52 - 00064024 _____ C:\Users\Wild-Pako\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-27 08:22 - 2013-09-27 08:22 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\OpenOffice
2013-09-27 08:19 - 2013-09-27 08:19 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk
2013-09-27 08:19 - 2013-09-27 08:18 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-09-27 08:14 - 2009-08-13 17:58 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3
2013-09-27 08:11 - 2013-09-22 18:16 - 00000000 ____D C:\Windows\system32\appmgmt
2013-09-26 20:17 - 2013-09-26 20:17 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2013-09-26 15:00 - 2013-09-26 15:00 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-09-26 15:00 - 2013-09-26 15:00 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-09-26 07:52 - 2013-09-26 07:52 - 00000000 _____ C:\Windows\setuperr.log
2013-09-25 22:15 - 2013-09-25 22:15 - 00000783 _____ C:\Users\Wild-Pako\Desktop\! - - Transfer - - !.lnk
2013-09-25 21:57 - 2013-09-25 21:57 - 00000000 ____D C:\ProgramData\Canneverbe Limited
2013-09-25 21:56 - 2013-09-25 21:56 - 00001913 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk
2013-09-25 21:56 - 2013-09-25 21:56 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Canneverbe Limited
2013-09-25 21:56 - 2013-09-25 21:56 - 00000000 ____D C:\Program Files (x86)\CDBurnerXP
2013-09-25 21:51 - 2013-09-25 21:51 - 00001501 _____ C:\Users\Wild-Pako\Desktop\Load.lnk
2013-09-25 21:34 - 2013-09-25 21:34 - 00001282 _____ C:\Users\Public\Desktop\EL3K My ELAS Remote Programmer.lnk
2013-09-25 21:34 - 2013-09-25 21:34 - 00000000 ____D C:\Program Files (x86)\Electronics Line
2013-09-25 20:41 - 2013-09-25 20:41 - 00002050 _____ C:\Users\Wild-Pako\Desktop\JDownloader.lnk
2013-09-25 20:41 - 2009-08-13 18:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-25 20:40 - 2013-09-25 20:40 - 00000000 ____D C:\Users\Wild-Pako\Programme
2013-09-25 20:31 - 2013-09-25 20:29 - 00000000 ____D C:\Windows\rescache
2013-09-25 19:59 - 2013-09-25 19:58 - 175636928 _____ C:\Users\Wild-Pako\Downloads\130254498000.rar.part
2013-09-25 19:59 - 2009-08-13 18:11 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Mozilla
2013-09-25 19:40 - 2013-09-25 19:39 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Google
2013-09-25 19:40 - 2013-09-25 19:39 - 00000000 ____D C:\Program Files (x86)\Google
2013-09-25 19:39 - 2013-09-25 19:39 - 00784872 _____ (Google Inc.) C:\Users\Wild-Pako\Downloads\ChromeSetup.exe
2013-09-25 19:38 - 2013-09-25 19:38 - 07990240 _____ (MPC-HC Team                                                 ) C:\Users\Wild-Pako\Downloads\MPC-HC.1.6.8.x64.exe
2013-09-25 19:38 - 2013-09-25 19:38 - 00001030 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-09-25 19:37 - 2013-09-25 19:37 - 23003252 _____ C:\Users\Wild-Pako\Downloads\vlc-2.0.8-win32.exe
2013-09-25 19:33 - 2009-08-13 17:20 - 00000000 ___RD C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-25 19:13 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-09-25 19:13 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-09-25 17:49 - 2009-07-14 09:46 - 00000000 ____D C:\Program Files\Windows Journal
2013-09-25 17:38 - 2013-09-25 17:38 - 00000000 ____D C:\ProgramData\Oracle
2013-09-25 17:36 - 2013-09-25 17:37 - 00868264 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-09-25 17:36 - 2013-09-25 17:37 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-09-25 17:36 - 2013-09-25 17:37 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-09-25 17:36 - 2013-09-25 17:37 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-09-25 17:36 - 2013-09-25 17:37 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-09-25 17:36 - 2010-10-02 14:28 - 00790440 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-09-25 17:36 - 2009-09-11 18:41 - 00000000 ____D C:\Program Files (x86)\Java
2013-09-25 17:28 - 2009-08-13 17:21 - 00001413 _____ C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\zh-HK
2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\tr-TR
2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-09-25 17:22 - 2013-09-24 19:14 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Winamp
2013-09-25 17:20 - 2013-09-25 17:20 - 02564703 _____ C:\Users\Wild-Pako\Downloads\CMI8738_WDM_0639XP.zip
2013-09-25 17:02 - 2013-09-25 16:55 - 00008799 _____ C:\Windows\IE10_main.log
2013-09-25 16:56 - 2013-09-25 16:56 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-09-25 16:56 - 2013-09-25 16:56 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-09-25 16:56 - 2013-09-25 16:56 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-09-25 16:56 - 2013-09-25 16:56 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-09-25 16:56 - 2013-09-25 16:56 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-09-25 16:56 - 2013-09-25 16:56 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-09-25 16:56 - 2013-09-25 16:56 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-09-25 16:56 - 2013-09-25 16:56 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-09-25 16:56 - 2013-09-25 16:56 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-09-25 16:39 - 2013-09-24 19:15 - 00000943 _____ C:\Users\Public\Desktop\Winamp.lnk
2013-09-25 16:39 - 2013-09-24 19:14 - 00000000 ____D C:\Program Files (x86)\Winamp
2013-09-25 16:38 - 2013-09-25 16:38 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in
2013-09-25 16:38 - 2013-09-25 16:38 - 00000000 ____D C:\Program Files (x86)\Winamp Detect
2013-09-25 16:37 - 2013-09-25 16:37 - 13385888 _____ (Nullsoft, Inc.) C:\Users\Wild-Pako\Downloads\winamp565_full_emusic-7plus_de-de.exe
2013-09-25 15:36 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-25 15:33 - 2009-08-13 18:04 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Adobe
2013-09-25 15:28 - 2009-08-13 18:06 - 00001111 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-09-23 01:28 - 2013-10-09 18:24 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-23 01:28 - 2013-10-09 18:24 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
         


Alt 13.10.2013, 00:06   #6
Wild-Pako
 
Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome - Standard

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome



Code:
ATTFilter
2013-09-23 01:27 - 2013-10-09 18:24 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-23 00:55 - 2013-10-09 18:24 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-23 00:55 - 2013-10-09 18:24 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-23 00:55 - 2013-10-09 18:24 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-23 00:54 - 2013-10-09 18:24 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-22 18:27 - 2009-09-18 16:00 - 00000000 ____D C:\Program Files (x86)\Zylom Games
2013-09-22 18:25 - 2009-08-13 21:00 - 00000000 ____D C:\Program Files (x86)\Vuze
2013-09-22 18:25 - 2009-08-13 18:11 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Mozilla
2013-09-22 18:24 - 2009-08-13 17:46 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\TerraTec
2013-09-22 18:21 - 2013-04-02 19:18 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-09-22 18:21 - 2009-08-13 18:02 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Apple Computer
2013-09-22 18:21 - 2009-08-13 18:00 - 00000000 ____D C:\ProgramData\Apple Computer
2013-09-22 18:16 - 2012-07-25 19:08 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\ArcSoft
2013-09-22 18:11 - 2013-09-22 18:11 - 00003196 _____ C:\Windows\System32\Tasks\{758CECE7-FCF0-43F8-9FAD-6E45BC86DE8D}
2013-09-22 17:53 - 2010-07-08 16:48 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-09-21 17:09 - 2009-10-07 17:59 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\HCM Updater
2013-09-21 05:38 - 2013-10-09 18:24 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-21 05:30 - 2013-10-09 18:24 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-21 04:48 - 2013-10-09 18:24 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-21 04:39 - 2013-10-09 18:24 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-20 19:54 - 2013-09-20 19:49 - 00466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2013-09-20 19:54 - 2013-09-20 19:49 - 00444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2013-09-20 19:54 - 2013-09-20 19:49 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2013-09-20 19:54 - 2013-09-20 19:49 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2013-09-20 19:54 - 2013-09-20 19:49 - 00000628 _____ C:\Users\Public\Desktop\3DMark06.lnk
2013-09-20 19:49 - 2013-09-20 19:49 - 00000000 ____D C:\Program Files (x86)\OpenAL
2013-09-20 19:47 - 2013-09-20 19:47 - 00000000 ____D C:\Program Files (x86)\Futuremark
2013-09-20 19:44 - 2013-09-20 19:44 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\ATI
2013-09-20 19:44 - 2013-09-20 19:44 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\ATI
2013-09-20 19:43 - 2013-09-20 19:43 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2013-09-18 19:40 - 2013-09-18 19:40 - 00000000 _____ C:\Windows\ativpsrm.bin
2013-09-18 19:39 - 2013-09-18 19:39 - 00000000 ____D C:\Program Files (x86)\AMD APP
2013-09-18 19:38 - 2013-09-18 19:38 - 00000000 ____D C:\Program Files\ATI

Files to move or delete:
====================
C:\Users\Wild-Pako\FLASHSPI.EXE


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-10-11 17:44

==================== End Of Log ============================
         

Alt 13.10.2013, 15:06   #7
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome - Standard

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome



Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!
Downloade dir bitte Combofix vom folgenden Downloadspiegel

Link 1


WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.


Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 13.10.2013, 15:31   #8
Wild-Pako
 
Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome - Standard

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome



Code:
ATTFilter
ComboFix 13-10-13.01 - Wild-Pako 13.10.2013  15:18:38.1.4 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.49.1031.18.6142.3288 [GMT 2:00]
ausgeführt von:: c:\users\Wild-Pako\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\#Short company name#
c:\programdata\#Short company name#\#settings_subfolder#\Timerlist.xml
c:\users\Wild-Pako\AppData\Roaming\#Short company name#
c:\users\Wild-Pako\AppData\Roaming\#Short company name#\#settings_subfolder#\#dvr.ini
c:\users\Wild-Pako\AppData\Roaming\#Short company name#\#settings_subfolder#\Log\VersionCheck.log
c:\users\Wild-Pako\AppData\Roaming\#Short company name#\#settings_subfolder#\Log\VersionCheck01.log
c:\windows\wininit.ini
.
.
(((((((((((((((((((((((   Dateien erstellt von 2013-09-13 bis 2013-10-13  ))))))))))))))))))))))))))))))
.
.
2013-10-13 13:24 . 2013-10-13 13:24	--------	d-----w-	c:\users\Default\AppData\Local\temp
2013-10-13 09:15 . 2013-10-13 09:15	--------	d-----w-	c:\users\Wild-Pako\AppData\Local\TransMac
2013-10-13 09:15 . 2013-10-13 09:15	--------	d-----w-	c:\program files (x86)\TransMac
2013-10-12 23:16 . 2013-10-12 23:16	--------	d-----w-	c:\program files (x86)\XeMu360
2013-10-12 18:10 . 2013-10-12 18:10	--------	d-----w-	C:\FRST
2013-10-12 17:48 . 2013-10-12 17:49	--------	d-----w-	C:\AdwCleaner
2013-10-12 15:56 . 2013-10-12 18:24	--------	d-----w-	c:\program files (x86)\Mozilla Thunderbird
2013-10-12 15:08 . 2013-10-12 15:08	--------	d-----w-	c:\users\Wild-Pako\AppData\Local\SCE
2013-10-11 13:19 . 2013-09-15 22:50	9694160	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{CE404130-0FE8-4176-A6D3-20F6AE8EE0CF}\mpengine.dll
2013-10-09 16:03 . 2013-07-04 12:50	633856	----a-w-	c:\windows\system32\comctl32.dll
2013-10-08 19:32 . 2013-10-08 19:32	--------	d-----w-	c:\programdata\Orbit
2013-10-08 18:31 . 2013-10-08 18:31	--------	d--h--w-	c:\program files (x86)\Common Files\EAInstaller
2013-10-08 17:58 . 2013-08-30 07:48	33400	----a-w-	c:\windows\system32\drivers\aswFsBlk.sys
2013-10-08 17:58 . 2013-08-30 07:48	378944	----a-w-	c:\windows\system32\drivers\aswSP.sys
2013-10-08 17:58 . 2013-08-30 07:48	72016	----a-w-	c:\windows\system32\drivers\aswRdr2.sys
2013-10-08 17:58 . 2013-08-30 07:48	64288	----a-w-	c:\windows\system32\drivers\aswTdi.sys
2013-10-08 17:58 . 2013-08-30 07:48	1030952	----a-w-	c:\windows\system32\drivers\aswSnx.sys
2013-10-08 17:58 . 2013-08-30 07:48	204880	----a-w-	c:\windows\system32\drivers\aswVmm.sys
2013-10-08 17:58 . 2013-08-30 07:48	65336	----a-w-	c:\windows\system32\drivers\aswRvrt.sys
2013-10-08 17:58 . 2013-08-30 07:48	80816	----a-w-	c:\windows\system32\drivers\aswMonFlt.sys
2013-10-08 17:58 . 2013-08-30 07:47	287840	----a-w-	c:\windows\system32\aswBoot.exe
2013-10-08 17:56 . 2013-08-30 07:47	41664	----a-w-	c:\windows\avastSS.scr
2013-10-08 17:56 . 2013-10-08 17:56	--------	d-----w-	c:\program files\AVAST Software
2013-10-08 17:52 . 2013-10-08 17:56	--------	d-----w-	c:\programdata\AVAST Software
2013-10-08 17:08 . 2013-10-08 17:08	--------	d-----w-	c:\programdata\Futuremark
2013-10-08 17:06 . 2013-10-08 17:06	--------	d-----w-	c:\program files (x86)\NVIDIA Corporation
2013-10-08 17:06 . 2013-10-08 17:06	--------	d-----w-	c:\program files (x86)\AGEIA Technologies
2013-10-07 19:38 . 2013-10-07 19:59	--------	d-----w-	c:\programdata\Spybot - Search & Destroy
2013-10-07 19:38 . 2009-01-25 11:14	17272	----a-w-	c:\windows\system32\sdnclean64.exe
2013-10-07 19:38 . 2013-10-07 19:39	--------	d-----w-	c:\program files (x86)\Spybot - Search & Destroy 2
2013-10-07 17:10 . 2013-10-07 17:10	--------	d-----w-	c:\programdata\ATI
2013-10-07 16:58 . 2013-10-07 16:58	--------	d-----w-	c:\programdata\AMD
2013-10-07 16:58 . 2013-10-07 16:58	--------	d-----w-	c:\program files (x86)\AMD AVT
2013-10-07 16:58 . 2013-10-07 16:58	--------	d-----w-	c:\program files (x86)\Common Files\ATI Technologies
2013-10-07 16:55 . 2013-10-07 16:55	--------	d-----w-	c:\program files\Common Files\ATI Technologies
2013-10-07 16:52 . 2013-10-07 16:53	--------	d-----w-	c:\programdata\Package Cache
2013-10-03 16:20 . 2013-10-03 16:26	25640	----a-w-	c:\windows\gdrv.sys
2013-10-03 13:26 . 2008-08-28 07:16	26351	----a-w-	c:\users\Wild-Pako\FLASHSPI.EXE
2013-10-02 21:03 . 2013-10-02 21:03	--------	d-----w-	c:\users\Wild-Pako\AppData\Roaming\Sinvise Systems
2013-10-02 21:03 . 2013-10-02 21:03	--------	d-----w-	c:\program files (x86)\Sinvise Systems
2013-10-02 19:24 . 2013-10-02 19:24	--------	d-----w-	c:\users\Wild-Pako\AppData\Roaming\Leadertech
2013-10-02 19:06 . 2013-10-02 19:06	--------	d-----w-	c:\programdata\Electronic Arts
2013-10-02 19:06 . 2013-10-02 19:06	--------	d-----w-	c:\programdata\EA Core
2013-10-01 10:42 . 2013-10-07 20:10	--------	d-----w-	c:\users\Wild-Pako\AppData\Local\CrossLoop
2013-09-29 11:43 . 2013-09-29 11:43	--------	d-----w-	c:\program files\Core Temp
2013-09-29 09:49 . 2013-09-29 09:49	49152	----a-r-	c:\users\Wild-Pako\AppData\Roaming\Microsoft\Installer\{AF80D8A3-CCEC-4CC2-BE6C-3E8512286993}\NewShortcut1_109A2A71E4394D28A5ACD8F8321BB21B.exe
2013-09-29 09:43 . 2013-09-29 09:43	49152	----a-r-	c:\users\Wild-Pako\AppData\Roaming\Microsoft\Installer\{12F865ED-8D74-427A-8F73-8687D37E9C5D}\NewShortcut2_B81EF528E6964545A57DCFB2387636B2.exe
2013-09-29 09:43 . 2013-09-29 09:43	49152	----a-r-	c:\users\Wild-Pako\AppData\Roaming\Microsoft\Installer\{12F865ED-8D74-427A-8F73-8687D37E9C5D}\NewShortcut1_D82E1A21FF374417B3E68D61F803C35D.exe
2013-09-28 20:35 . 2013-09-28 20:35	--------	d-----w-	c:\program files\Uninstaller
2013-09-28 20:32 . 2013-09-28 20:32	--------	d-----w-	c:\program files\CPUID
2013-09-28 20:31 . 2013-09-28 20:33	--------	d-----w-	c:\program files (x86)\Feven 1.5
2013-09-28 20:12 . 2013-09-28 20:12	--------	d-----w-	c:\program files\Defraggler
2013-09-28 20:07 . 2013-09-28 20:07	--------	d-----w-	c:\users\Wild-Pako\AppData\Local\avgchrome
2013-09-28 19:41 . 2013-09-28 19:41	--------	d-----w-	c:\users\Wild-Pako\AppData\Local\2K Games
2013-09-28 16:00 . 2013-09-28 16:00	--------	d-----w-	c:\program files (x86)\Microsoft.NET
2013-09-28 11:51 . 2013-09-28 11:51	--------	d-----w-	c:\program files (x86)\FileZilla FTP Client
2013-09-27 21:05 . 2013-09-27 21:05	--------	d-----w-	c:\users\Wild-Pako\AppData\Local\Rockstar Games
2013-09-27 21:05 . 2013-09-27 21:05	--------	d-sh--w-	c:\programdata\SecuROM
2013-09-27 20:54 . 2013-09-27 20:54	--------	d-----w-	c:\windows\SysWow64\xlive
2013-09-27 20:54 . 2013-09-27 20:54	--------	d-----w-	c:\program files (x86)\Microsoft Games for Windows - LIVE
2013-09-27 20:52 . 2007-03-05 10:42	15128	----a-w-	c:\windows\SysWow64\x3daudio1_1.dll
2013-09-27 15:14 . 2013-09-27 15:18	--------	d-----w-	C:\tempvideo
2013-09-27 10:43 . 2013-09-27 10:43	--------	d-----w-	c:\programdata\Hagel Technologies
2013-09-27 10:43 . 2013-09-27 10:45	--------	d-----w-	c:\program files (x86)\DU Meter
2013-09-27 10:20 . 2013-10-13 09:03	--------	d-----w-	c:\users\Wild-Pako\AppData\Roaming\Dropbox
2013-09-27 06:22 . 2013-09-27 06:22	--------	d-----w-	c:\users\Wild-Pako\AppData\Roaming\OpenOffice
2013-09-27 06:18 . 2013-09-27 06:19	--------	d-----w-	c:\program files (x86)\OpenOffice 4
2013-09-26 18:17 . 2013-09-26 18:17	--------	d-----w-	c:\program files (x86)\TeamViewer
2013-09-26 13:00 . 2013-09-26 13:00	--------	d-----w-	c:\windows\SysWow64\searchplugins
2013-09-26 13:00 . 2013-09-26 13:00	--------	d-----w-	c:\windows\SysWow64\Extensions
2013-09-25 19:57 . 2013-09-25 19:57	--------	d-----w-	c:\programdata\Canneverbe Limited
2013-09-25 19:56 . 2013-09-25 19:56	--------	d-----w-	c:\users\Wild-Pako\AppData\Roaming\Canneverbe Limited
2013-09-25 19:56 . 2013-09-25 19:56	--------	d-----w-	c:\program files (x86)\CDBurnerXP
2013-09-25 19:34 . 2013-09-25 19:34	--------	d-----w-	c:\program files (x86)\Electronics Line
2013-09-25 18:40 . 2013-09-25 18:40	--------	d-----w-	c:\users\Wild-Pako\Programme
2013-09-25 18:29 . 2013-09-25 18:31	--------	d-----w-	c:\windows\rescache
2013-09-25 17:39 . 2013-09-25 17:40	--------	d-----w-	c:\users\Wild-Pako\AppData\Local\Google
2013-09-25 17:39 . 2013-09-25 17:40	--------	d-----w-	c:\program files (x86)\Google
2013-09-25 17:39 . 2013-10-04 20:11	--------	d-----w-	c:\program files\MPC-HC
2013-09-25 17:07 . 2013-10-09 16:23	--------	d-----w-	c:\windows\system32\MRT
2013-09-25 15:59 . 2013-08-02 02:23	5550528	----a-w-	c:\windows\system32\ntoskrnl.exe
2013-09-25 15:43 . 2013-02-27 05:48	1930752	----a-w-	c:\windows\system32\authui.dll
2013-09-25 15:38 . 2013-04-09 23:34	1247744	----a-w-	c:\windows\SysWow64\DWrite.dll
2013-09-25 15:38 . 2013-04-02 22:51	1643520	----a-w-	c:\windows\system32\DWrite.dll
2013-09-25 15:38 . 2013-09-25 15:38	--------	d-----w-	c:\programdata\Oracle
2013-09-25 15:37 . 2013-09-25 15:37	--------	d-----w-	c:\program files (x86)\Common Files\Java
2013-09-25 15:37 . 2013-09-25 15:36	868264	----a-w-	c:\windows\SysWow64\npDeployJava1.dll
2013-09-25 15:37 . 2013-09-25 15:36	96168	----a-w-	c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-09-25 15:02 . 2012-07-26 07:46	2560	----a-w-	c:\windows\system32\drivers\de-DE\wdf01000.sys.mui
2013-09-25 15:02 . 2012-07-26 04:55	54376	----a-w-	c:\windows\system32\drivers\WdfLdr.sys
2013-09-25 15:02 . 2012-07-26 04:47	2560	----a-w-	c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2013-09-25 15:02 . 2012-07-26 02:36	9728	----a-w-	c:\windows\system32\Wdfres.dll
2013-09-25 14:54 . 2012-08-23 15:09	3584	----a-w-	c:\windows\system32\drivers\de-DE\tsusbflt.sys.mui
2013-09-25 14:51 . 2012-07-26 03:08	84992	----a-w-	c:\windows\system32\WUDFSvc.dll
2013-09-25 14:51 . 2012-07-26 02:26	87040	----a-w-	c:\windows\system32\drivers\WUDFPf.sys
2013-09-25 14:51 . 2012-07-26 02:26	198656	----a-w-	c:\windows\system32\drivers\WUDFRd.sys
2013-09-25 14:51 . 2012-07-26 03:08	229888	----a-w-	c:\windows\system32\WUDFHost.exe
2013-09-25 14:51 . 2012-07-26 03:08	744448	----a-w-	c:\windows\system32\WUDFx.dll
2013-09-25 14:51 . 2012-07-26 03:08	45056	----a-w-	c:\windows\system32\WUDFCoinstaller.dll
2013-09-25 14:51 . 2012-07-26 03:08	194048	----a-w-	c:\windows\system32\WUDFPlatform.dll
2013-09-25 14:46 . 2012-12-07 13:20	441856	----a-w-	c:\windows\system32\Wpc.dll
2013-09-25 14:42 . 2011-05-04 05:25	2315776	----a-w-	c:\windows\system32\tquery.dll
2013-09-25 14:39 . 2009-09-04 15:29	1892184	----a-w-	c:\windows\SysWow64\D3DX9_42.dll
2013-09-25 14:39 . 2006-09-28 14:05	2414360	----a-w-	c:\windows\SysWow64\d3dx9_31.dll
2013-09-25 14:38 . 2013-09-25 14:38	--------	d-----w-	c:\program files (x86)\Winamp Detect
2013-09-25 14:38 . 2013-09-25 14:38	--------	d-----w-	c:\program files (x86)\Common Files\PX Storage Engine
2013-09-25 13:28 . 2013-09-11 02:28	271256	----a-w-	c:\program files (x86)\Mozilla Firefox\browser\components\browsercomps.dll
2013-09-25 13:28 . 2013-09-11 02:27	107416	----a-w-	c:\program files (x86)\Mozilla Firefox\webapprt-stub.exe
2013-09-25 13:28 . 2013-09-11 02:27	170232	----a-w-	c:\program files (x86)\Mozilla Firefox\webapp-uninstaller.exe
2013-09-25 13:28 . 2013-09-11 02:27	27544	----a-w-	c:\program files (x86)\Mozilla Firefox\plugin-hang-ui.exe
2013-09-25 13:28 . 2013-09-11 02:26	74648	----a-w-	c:\program files (x86)\Mozilla Firefox\breakpadinjector.dll
2013-09-24 17:14 . 2011-03-04 19:44	133616	------w-	c:\windows\SysWow64\pxafs.dll
2013-09-24 17:14 . 2013-09-25 15:22	--------	d-----w-	c:\users\Wild-Pako\AppData\Roaming\Winamp
2013-09-24 17:14 . 2013-09-25 14:39	--------	d-----w-	c:\program files (x86)\Winamp
2013-09-22 16:16 . 2013-09-27 06:11	--------	d-----w-	c:\windows\system32\appmgmt
2013-09-22 08:15 . 2013-09-22 08:18	--------	d-----w-	c:\program files (x86)\Common Files\Wise Installation Wizard
2013-09-20 17:52 . 2005-12-05 16:09	3815120	----a-w-	c:\windows\system32\d3dx9_28.dll
2013-09-20 17:49 . 2013-09-20 17:54	466456	----a-w-	c:\windows\system32\wrap_oal.dll
2013-09-20 17:49 . 2013-09-20 17:54	444952	----a-w-	c:\windows\SysWow64\wrap_oal.dll
2013-09-20 17:49 . 2013-09-20 17:54	122904	----a-w-	c:\windows\system32\OpenAL32.dll
2013-09-20 17:49 . 2013-09-20 17:54	109080	----a-w-	c:\windows\SysWow64\OpenAL32.dll
2013-09-20 17:49 . 2013-09-20 17:49	--------	d-----w-	c:\program files (x86)\OpenAL
2013-09-20 17:47 . 2013-09-20 17:47	--------	d-----w-	c:\program files (x86)\Futuremark
2013-09-20 17:44 . 2013-09-20 17:44	--------	d-----w-	c:\users\Wild-Pako\AppData\Roaming\ATI
2013-09-20 17:44 . 2013-09-20 17:44	--------	d-----w-	c:\users\Wild-Pako\AppData\Local\ATI
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-09 16:38 . 2012-07-31 18:20	71048	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-09 16:38 . 2012-07-31 18:20	692616	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2013-10-09 16:22 . 2010-10-02 12:30	80541720	----a-w-	c:\windows\system32\MRT.exe
2013-09-29 16:23 . 2009-08-18 10:49	564632	----a-w-	c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2013-09-29 16:23 . 2009-08-18 09:24	22240	----a-w-	c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-09-28 18:02 . 2010-08-07 20:58	43520	----a-w-	c:\windows\SysWow64\CmdLineExt03.dll
2013-09-25 15:36 . 2010-10-02 12:28	790440	----a-w-	c:\windows\SysWow64\deployJava1.dll
2013-08-31 00:14 . 2013-08-31 00:14	78432	----a-w-	c:\windows\system32\atimpc64.dll
2013-08-31 00:14 . 2013-08-31 00:14	78432	----a-w-	c:\windows\system32\amdpcom64.dll
2013-08-31 00:14 . 2013-08-31 00:14	71704	----a-w-	c:\windows\SysWow64\atimpc32.dll
2013-08-31 00:14 . 2013-08-31 00:14	71704	----a-w-	c:\windows\SysWow64\amdpcom32.dll
2013-08-31 00:14 . 2013-08-31 00:14	142792	----a-w-	c:\windows\system32\atiuxp64.dll
2013-08-31 00:14 . 2013-08-31 00:14	125824	----a-w-	c:\windows\SysWow64\atiuxpag.dll
2013-08-31 00:13 . 2013-08-31 00:13	97984	----a-w-	c:\windows\SysWow64\atiu9pag.dll
2013-08-31 00:13 . 2013-08-31 00:13	114488	----a-w-	c:\windows\system32\atiu9p64.dll
2013-08-31 00:13 . 2013-08-31 00:13	1233080	----a-w-	c:\windows\system32\aticfx64.dll
2013-08-31 00:13 . 2013-08-31 00:13	1027544	----a-w-	c:\windows\SysWow64\aticfx32.dll
2013-08-31 00:13 . 2013-08-31 00:13	9464840	----a-w-	c:\windows\system32\atidxx64.dll
2013-08-31 00:13 . 2013-08-31 00:13	8215992	----a-w-	c:\windows\SysWow64\atidxx32.dll
2013-08-31 00:13 . 2013-08-31 00:13	6176008	----a-w-	c:\windows\SysWow64\atiumdva.dll
2013-08-31 00:13 . 2013-08-31 00:13	6189416	----a-w-	c:\windows\SysWow64\atiumdag.dll
2013-08-31 00:13 . 2013-08-31 00:13	6767240	----a-w-	c:\windows\system32\atiumd6a.dll
2013-08-31 00:13 . 2013-08-31 00:13	7256496	----a-w-	c:\windows\system32\atiumd64.dll
2013-08-31 00:11 . 2013-08-31 00:11	12528640	----a-w-	c:\windows\system32\drivers\atikmdag.sys
2013-08-30 23:48 . 2013-08-30 23:48	127488	----a-w-	c:\windows\system32\coinst_13.152.dll
2013-08-30 23:48 . 2013-08-30 23:48	229376	----a-w-	c:\windows\system32\clinfo.exe
2013-08-30 23:47 . 2013-08-30 23:47	995342	----a-w-	c:\windows\SysWow64\amdocl_as32.exe
2013-08-30 23:47 . 2013-08-30 23:47	798734	----a-w-	c:\windows\SysWow64\amdocl_ld32.exe
2013-08-30 23:47 . 2013-08-30 23:47	1187342	----a-w-	c:\windows\system32\amdocl_as64.exe
2013-08-30 23:47 . 2013-08-30 23:47	1061902	----a-w-	c:\windows\system32\amdocl_ld64.exe
2013-08-30 23:47 . 2013-08-30 23:47	98816	----a-w-	c:\windows\system32\OpenVideo64.dll
2013-08-30 23:47 . 2013-08-30 23:47	83456	----a-w-	c:\windows\SysWow64\OpenVideo.dll
2013-08-30 23:47 . 2013-08-30 23:47	86528	----a-w-	c:\windows\system32\OVDecode64.dll
2013-08-30 23:47 . 2013-08-30 23:47	73216	----a-w-	c:\windows\SysWow64\OVDecode.dll
2013-08-30 23:47 . 2013-08-30 23:47	28192256	----a-w-	c:\windows\system32\amdocl64.dll
2013-08-30 23:45 . 2013-08-30 23:45	23760896	----a-w-	c:\windows\SysWow64\amdocl.dll
2013-08-30 23:43 . 2013-08-30 23:43	63488	----a-w-	c:\windows\system32\OpenCL.dll
2013-08-30 23:43 . 2013-08-30 23:43	57344	----a-w-	c:\windows\SysWow64\OpenCL.dll
2013-08-30 23:35 . 2013-08-30 23:35	25387520	----a-w-	c:\windows\system32\atio6axx.dll
2013-08-30 23:18 . 2013-08-30 23:18	368640	----a-w-	c:\windows\system32\atiapfxx.exe
2013-08-30 23:18 . 2013-08-30 23:18	62464	----a-w-	c:\windows\system32\aticalrt64.dll
2013-08-30 23:18 . 2013-08-30 23:18	52224	----a-w-	c:\windows\SysWow64\aticalrt.dll
2013-08-30 23:18 . 2013-08-30 23:18	55808	----a-w-	c:\windows\system32\aticalcl64.dll
2013-08-30 23:18 . 2013-08-30 23:18	49152	----a-w-	c:\windows\SysWow64\aticalcl.dll
2013-08-30 23:17 . 2013-08-30 23:17	15716352	----a-w-	c:\windows\system32\aticaldd64.dll
2013-08-30 23:14 . 2013-08-30 23:14	14302208	----a-w-	c:\windows\SysWow64\aticaldd.dll
2013-08-30 23:13 . 2013-08-30 23:13	21400064	----a-w-	c:\windows\SysWow64\atioglxx.dll
2013-08-30 22:59 . 2013-08-30 22:59	442368	----a-w-	c:\windows\system32\atidemgy.dll
2013-08-30 22:58 . 2013-08-30 22:58	26112	----a-w-	c:\windows\system32\atimuixx.dll
2013-08-30 22:58 . 2013-08-30 22:58	571904	----a-w-	c:\windows\system32\atieclxx.exe
2013-08-30 22:57 . 2013-08-30 22:57	239616	----a-w-	c:\windows\system32\atiesrxx.exe
2013-08-30 22:56 . 2013-08-30 22:56	190976	----a-w-	c:\windows\system32\atitmm64.dll
2013-08-30 22:33 . 2010-02-11 04:48	784384	----a-w-	c:\windows\system32\atiadlxx.dll
2013-08-30 22:33 . 2013-08-30 22:33	594944	----a-w-	c:\windows\SysWow64\atiadlxy.dll
2013-08-30 22:33 . 2013-08-30 22:33	43520	----a-w-	c:\windows\system32\drivers\ati2erec.dll
2013-08-30 22:32 . 2013-08-30 22:32	75264	----a-w-	c:\windows\system32\atig6pxx.dll
2013-08-30 22:32 . 2013-08-30 22:32	69632	----a-w-	c:\windows\SysWow64\atiglpxx.dll
2013-08-30 22:32 . 2013-08-30 22:32	69632	----a-w-	c:\windows\system32\atiglpxx.dll
2013-08-30 22:32 . 2013-08-30 22:32	100352	----a-w-	c:\windows\system32\atig6txx.dll
2013-08-30 22:32 . 2013-08-30 22:32	96768	----a-w-	c:\windows\SysWow64\atigktxx.dll
2013-08-30 22:32 . 2013-08-30 22:32	618496	----a-w-	c:\windows\system32\drivers\atikmpag.sys
2013-08-30 17:58 . 2013-08-30 17:58	51200	----a-w-	c:\windows\system32\kdbsdk64.dll
2013-08-30 17:53 . 2013-08-30 17:53	38912	----a-w-	c:\windows\SysWow64\kdbsdk32.dll
2013-08-07 02:22 . 2009-10-03 12:03	278800	------w-	c:\windows\system32\MpSigStub.exe
2013-08-02 01:48 . 2013-09-25 15:59	44032	----a-w-	c:\windows\apppatch\acwow64.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-06-05 17:17	130736	----a-w-	c:\users\Wild-Pako\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-06-05 17:17	130736	----a-w-	c:\users\Wild-Pako\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-06-05 17:17	130736	----a-w-	c:\users\Wild-Pako\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-06-05 17:17	130736	----a-w-	c:\users\Wild-Pako\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DU Meter"="c:\program files (x86)\DU Meter\DUMeter.exe" [2013-09-27 2749984]
"Spybot-S&D Cleaning"="c:\program files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" [2013-05-16 3642312]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2013-08-30 766208]
"SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2013-07-25 5624784]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-08-30 4858968]
.
c:\users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Core Temp.lnk - c:\program files\Core Temp\Core Temp.exe [2013-9-29 856016]
Dropbox.lnk - c:\users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-6-5 27370808]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"SoftwareSASGeneration"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute	REG_MULTI_SZ   	autocheck autochk *\0\0sdnclean64.exe
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x]
R3 cpuz135;cpuz135;c:\users\WILD-P~1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys;c:\users\WILD-P~1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [x]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [x]
R3 MTSBDA;Cinergy S2 BDA service;c:\windows\system32\DRIVERS\MtsBda.sys;c:\windows\SYSNATIVE\DRIVERS\MtsBda.sys [x]
R3 MtsHID;Cinergy C/S2 PCI HID service;c:\windows\system32\DRIVERS\MtsHid.sys;c:\windows\SYSNATIVE\DRIVERS\MtsHid.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R4 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 DUMeterSvc;DU Meter Service;c:\program files (x86)\DU Meter\DUMeterSvc.exe;c:\program files (x86)\DU Meter\DUMeterSvc.exe [x]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [x]
S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [x]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S3 ALSysIO;ALSysIO;c:\users\WILD-P~1\AppData\Local\Temp\ALSysIO64.sys;c:\users\WILD-P~1\AppData\Local\Temp\ALSysIO64.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-10-07 22:45	1185744	----a-w-	c:\program files (x86)\Google\Chrome\Application\30.0.1599.69\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-10-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-31 16:38]
.
2013-10-13 c:\windows\Tasks\Feven 1.5-chromeinstaller.job
- c:\program files (x86)\Feven 1.5\Feven 1.5-chromeinstaller.exe [2013-09-28 20:31]
.
2013-10-13 c:\windows\Tasks\Feven 1.5-codedownloader.job
- c:\program files (x86)\Feven 1.5\Feven 1.5-codedownloader.exe [2013-09-28 20:33]
.
2013-10-13 c:\windows\Tasks\Feven 1.5-enabler.job
- c:\program files (x86)\Feven 1.5\Feven 1.5-enabler.exe [2013-09-28 20:33]
.
2013-10-13 c:\windows\Tasks\Feven 1.5-firefoxinstaller.job
- c:\program files (x86)\Feven 1.5\Feven 1.5-firefoxinstaller.exe [2013-09-28 20:32]
.
2013-10-13 c:\windows\Tasks\Feven 1.5-updater.job
- c:\program files (x86)\Feven 1.5\Feven 1.5-updater.exe [2013-09-28 20:33]
.
2013-10-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-25 17:39]
.
2013-10-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-25 17:39]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-08-30 07:47	133840	----a-w-	c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-06-05 17:17	164016	----a-w-	c:\users\Wild-Pako\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-06-05 17:17	164016	----a-w-	c:\users\Wild-Pako\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-06-05 17:17	164016	----a-w-	c:\users\Wild-Pako\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-06-05 17:17	164016	----a-w-	c:\users\Wild-Pako\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-06-25 7883296]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-06-25 1833504]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=6CFE001FD08EC324&affID=120523&tt=240913_238&tsp=5019
mLocal Page = c:\windows\SysWOW64\blank.htm
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.0.1 192.168.0.2
DPF: {971FC730-55F1-461F-83FD-B3BF5E1F039E} - hxxp://wg.dyndns.ws/AVC_AX_742.cab
FF - ProfilePath - c:\users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\
FF - ExtSQL: 2013-09-28 22:33; 249911bc-d1bd-4d66-8c17-df533609e6d8@c76f3de9-939e-4922-b73c-5d7a3139375d.com; c:\users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\extensions\249911bc-d1bd-4d66-8c17-df533609e6d8@c76f3de9-939e-4922-b73c-5d7a3139375d.com
FF - ExtSQL: 2013-10-06 20:22; adblockpopups@jessehakanen.net; c:\users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\extensions\adblockpopups@jessehakanen.net.xpi
FF - ExtSQL: 2013-10-07 21:30; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - ExtSQL: 2013-10-08 19:57; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: 2013-10-10 19:02; {3d7eb24f-2740-49df-8937-200b1cc08f8a}; c:\users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
.
.
------- Dateityp-Verknüpfung -------
.
JSEFile=%SystemRoot%\SysWow64\CScript.exe "%1" %*
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-Remote Control Editor - c:\program files (x86)\Common Files\TerraTec\Remote\TTTvRc.exe
Wow6432Node-HKCU-Run-MobileDocuments - c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe
Wow6432Node-HKCU-Run-CrossLoop - c:\users\Wild-Pako\AppData\Local\CrossLoop\CrossLoopConnect.exe
Notify-SDWinLogon - SDWinLogon.dll
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-CrossLoop_is1 - c:\users\Wild-Pako\AppData\Local\CrossLoop\unins000.exe
AddRemove-FMS - d:\fms\Uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DUMeterSvc]
"ImagePath"="c:\program files (x86)\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3470926038-3106149513-4058150324-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{762233AF-A805-52A0-ED1A-E354D2EA0822}*]
"paojgldoldphmghcbnplaikokdplmelp"=hex:6b,61,6a,6a,64,6e,62,6d,67,65,62,69,65,
   68,62,61,66,6b,6a,67,6e,66,00,00
"oamjhkofbemkilijfbinnknafcgghf"=hex:6b,61,6a,6a,64,6e,62,6d,67,65,62,69,65,68,
   62,61,66,6b,6a,67,6e,66,00,00
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-10-13  15:26:40
ComboFix-quarantined-files.txt  2013-10-13 13:26
.
Vor Suchlauf: 5.755.215.872 Bytes frei
Nach Suchlauf: 5.638.819.840 Bytes frei
.
- - End Of File - - 1A839589BDD099142F2E5F251F207A13
A36C5E4F47E84449FF07ED3517B43A31
         

Alt 14.10.2013, 09:06   #9
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome - Standard

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 14.10.2013, 19:23   #10
Wild-Pako
 
Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome - Standard

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome



Hi,

hier die Logs

Code:
ATTFilter
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.10.14.08

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16721
Wild-Pako :: WILD-PAKO-PC [Administrator]

14.10.2013 18:51:50
mbam-log-2013-10-14 (18-51-50).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 205967
Laufzeit: 2 Minute(n), 49 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 1
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.StartPage.A) -> Bösartig: (hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=6CFE001FD08EC324&affID=120523&tt=240913_238&tsp=5019) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt.

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Users\Wild-Pako\Downloads\cpu-z.exe (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)
         
Code:
ATTFilter
# AdwCleaner v3.007 - Bericht erstellt am 14/10/2013 um 19:03:38
# Updated 09/10/2013 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzername : Wild-Pako - WILD-PAKO-PC
# Gestartet von : C:\Users\Wild-Pako\Desktop\adwcleaner(1).exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Datei Gelöscht : C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\invalidprefs.js

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}]

***** [ Browser ] *****

-\\ Internet Explorer v10.0.9200.16720


-\\ Mozilla Firefox v24.0 (de)

[ Datei : C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\prefs.js ]


-\\ Google Chrome v30.0.1599.69

[ Datei : C:\Users\Wild-Pako\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Gelöscht : homepage
Gelöscht : icon_url
Gelöscht : search_url
Gelöscht : keyword
Gelöscht : urls_to_restore_on_startup

*************************

AdwCleaner[R0].txt - [7042 octets] - [12/10/2013 19:48:07]
AdwCleaner[R1].txt - [2447 octets] - [14/10/2013 19:01:56]
AdwCleaner[S0].txt - [6632 octets] - [12/10/2013 19:48:51]
AdwCleaner[S1].txt - [2352 octets] - [14/10/2013 19:03:38]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2412 octets] ##########
         
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.4 (10.06.2013:1)
OS: Windows 7 Ultimate x64
Ran by Wild-Pako on 14.10.2013 at 19:08:16,51
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3470926038-3106149513-4058150324-1001\Software\SweetIM



~~~ Files



~~~ Folders



~~~ FireFox

Successfully deleted: [Folder] C:\Users\Wild-Pako\AppData\Roaming\mozilla\firefox\profiles\kueee1xm.default\extensions\249911bc-d1bd-4d66-8c17-df533609e6d8@c76f3de9-939e-4922-b73c-5d7a3139375d.com
Emptied folder: C:\Users\Wild-Pako\AppData\Roaming\mozilla\firefox\profiles\kueee1xm.default\minidumps [31 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 14.10.2013 at 19:14:57,91
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013
Ran by Wild-Pako (administrator) on WILD-PAKO-PC on 14-10-2013 19:15:55
Running from D:\! - - Transfer - - !
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Hagel Technologies Ltd.) C:\Program Files (x86)\DU Meter\DUMeterSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Hagel Technologies Ltd.) C:\Program Files (x86)\DU Meter\DUMeter.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Samsung) K:\Program Files (x86)\Kies\Kies\Kies.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Samsung) K:\Program Files (x86)\Kies\Kies\External\FirmwareUpdate\KiesPDLR.exe
() C:\Program Files\Core Temp\Core Temp.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Samsung Electronics Co., Ltd.) K:\Program Files (x86)\Kies\Kies\KiesTrayAgent.exe
(Dropbox, Inc.) C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\system32\taskmgr.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7883296 2009-06-25] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-06-25] (Realtek Semiconductor Corp.)
HKCU\...\Run: [DU Meter] - C:\Program Files (x86)\DU Meter\DUMeter.exe [2749984 2013-09-27] (Hagel Technologies Ltd.)
HKCU\...\Run: [Spybot-S&D Cleaning] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3642312 2013-05-16] (Safer-Networking Ltd.)
HKCU\...\Run: [KiesPreload] - K:\Program Files (x86)\Kies\Kies\Kies.exe [1564528 2013-09-04] (Samsung)
HKCU\...\Run: [KiesAirMessage] - K:\Program Files (x86)\Kies\Kies\KiesAirMessage.exe -startup
HKCU\...\Run: [] - K:\Program Files (x86)\Kies\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656 2013-09-04] (Samsung)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-08-30] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software)
HKLM-x32\...\Run: [KiesTrayAgent] - K:\Program Files (x86)\Kies\Kies\KiesTrayAgent.exe [311152 2013-09-04] (Samsung Electronics Co., Ltd.)
Startup: C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Core Temp.lnk
ShortcutTarget: Core Temp.lnk -> C:\Program Files\Core Temp\Core Temp.exe ()
Startup: C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x01E862F5F4B9CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1286050903776
DPF: HKLM-x32 {971FC730-55F1-461F-83FD-B3BF5E1F039E} hxxp://wg.dyndns.ws/AVC_AX_742.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2

FireFox:
========
FF ProfilePath: C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\foxmarks@kei.com
FF Extension: VLC Media Player - Web Plugin - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\vlcplugin@radicalsoft.com
FF Extension: Flagfox - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
FF Extension: Flashblock - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
FF Extension: adblockpopups - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\adblockpopups@jessehakanen.net.xpi
FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi
FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}.xpi
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF

Chrome: 
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR DefaultSearchURL: (SearchGol) - hxxp://www.google.com
CHR DefaultSuggestURL: (SearchGol) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U40) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll No File
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll No File
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.400.43) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (Google Docs) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (Feven 1.5) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.24.28_0
CHR Extension: (YouTube) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR Extension: (Gmail) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software)
R2 DUMeterSvc; C:\Program Files (x86)\DU Meter\DUMeterSvc.exe [1391136 2009-09-04] (Hagel Technologies Ltd.)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.)
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [x]

==================== Drivers (Whitelisted) ====================

R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-10-25] (DT Soft Ltd)
S3 gdrv; C:\Windows\gdrv.sys [25640 2013-10-03] (Windows (R) Server 2003 DDK provider)
S3 gdrv; C:\Windows\gdrv.sys [25640 2013-10-03] (Windows (R) Server 2003 DDK provider)
S3 MTSBDA; C:\Windows\System32\DRIVERS\MtsBda.sys [322080 2008-12-01] (TerraTec Provide)
S3 MtsHID; C:\Windows\System32\DRIVERS\MtsHid.sys [27168 2008-12-01] (TerraTec Provide)
S1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R1 truecrypt; C:\Windows\SysWow64\drivers\truecrypt.sys [221376 2009-08-15] (TrueCrypt Foundation)
R1 truecrypt; C:\Windows\SysWow64\drivers\truecrypt.sys [221376 2009-08-15] (TrueCrypt Foundation)
R3 ALSysIO; \??\C:\Users\WILD-P~1\AppData\Local\Temp\ALSysIO64.sys [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 cpuz135; \??\C:\Users\WILD-P~1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [x]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x]
S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [x]
S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-10-14 19:14 - 2013-10-14 19:14 - 00001254 _____ C:\Users\Wild-Pako\Desktop\JRT.txt
2013-10-14 19:08 - 2013-10-14 19:08 - 00000000 ____D C:\Windows\ERUNT
2013-10-14 19:01 - 2013-10-14 19:01 - 01032220 _____ (Thisisu) C:\Users\Wild-Pako\Desktop\JRT.exe
2013-10-14 19:00 - 2013-10-14 19:00 - 01048960 _____ C:\Users\Wild-Pako\Desktop\adwcleaner(1).exe
2013-10-14 18:49 - 2013-10-14 18:49 - 00001073 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-10-14 18:49 - 2013-10-14 18:49 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Malwarebytes
2013-10-14 18:49 - 2013-10-14 18:49 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-14 18:49 - 2013-10-14 18:49 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-14 18:49 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-10-13 17:14 - 2013-10-13 17:20 - 00000592 _____ C:\Users\Wild-Pako\ashot.log
2013-10-13 17:14 - 2013-10-13 17:14 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\mightypocket
2013-10-13 17:13 - 2013-10-13 17:13 - 00000000 ____D C:\Program Files (x86)\Android Screen Capture
2013-10-13 17:09 - 2013-10-13 17:09 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2013-10-13 17:08 - 2013-10-13 17:08 - 00000000 ____D C:\Users\Wild-Pako\.android
2013-10-13 17:07 - 2013-10-13 17:07 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\MyPhoneExplorer
2013-10-13 17:07 - 2013-10-13 17:07 - 00000000 ____D C:\Program Files (x86)\MyPhoneExplorer
2013-10-13 17:02 - 2013-10-13 17:02 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log
2013-10-13 17:02 - 2013-10-13 17:02 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-10-13 17:01 - 2013-10-13 17:01 - 00000000 ____D C:\Users\Wild-Pako\Documents\samsung
2013-10-13 17:01 - 2013-10-13 17:01 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Samsung
2013-10-13 17:01 - 2013-10-13 17:01 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Samsung
2013-10-13 17:01 - 2013-06-21 02:07 - 00203672 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys
2013-10-13 17:01 - 2013-06-21 02:07 - 00103448 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys
2013-10-13 17:00 - 2013-07-18 14:33 - 04659712 _____ (Dmitry Streblechenko) C:\Windows\SysWOW64\Redemption.dll
2013-10-13 17:00 - 2013-07-18 14:32 - 00821824 _____ (Devguru Co., Ltd.) C:\Windows\SysWOW64\dgderapi.dll
2013-10-13 16:59 - 2013-10-13 17:01 - 00000000 ____D C:\ProgramData\Samsung
2013-10-13 16:58 - 2013-10-13 16:58 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Downloaded Installations
2013-10-13 15:26 - 2013-10-13 15:26 - 00035713 _____ C:\ComboFix.txt
2013-10-13 15:17 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-10-13 15:17 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-10-13 15:17 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-10-13 15:17 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-10-13 15:17 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-10-13 15:17 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-10-13 15:17 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-10-13 15:17 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-10-13 15:14 - 2013-10-13 15:26 - 00000000 ____D C:\Qoobox
2013-10-13 15:13 - 2013-10-13 15:25 - 00000000 ____D C:\Windows\erdnt
2013-10-13 15:13 - 2013-10-13 15:13 - 05132083 ____R (Swearware) C:\Users\Wild-Pako\Desktop\ComboFix.exe
2013-10-13 11:15 - 2013-10-13 11:15 - 00000971 _____ C:\Users\Wild-Pako\Desktop\TransMac.lnk
2013-10-13 11:15 - 2013-10-13 11:15 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TransMac
2013-10-13 11:15 - 2013-10-13 11:15 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\TransMac
2013-10-13 11:15 - 2013-10-13 11:15 - 00000000 ____D C:\Program Files (x86)\TransMac
2013-10-13 01:16 - 2013-10-13 01:16 - 00000000 ____D C:\Program Files (x86)\XeMu360
2013-10-12 20:10 - 2013-10-12 20:10 - 00000000 ____D C:\FRST
2013-10-12 20:09 - 2013-10-12 20:09 - 00000168 _____ C:\Users\Wild-Pako\defogger_reenable
2013-10-12 19:48 - 2013-10-14 19:03 - 00000000 ____D C:\AdwCleaner
2013-10-12 17:56 - 2013-10-12 20:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-10-12 17:08 - 2013-10-12 17:08 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\SCE
2013-10-12 17:07 - 2013-10-12 17:07 - 00000810 _____ C:\Users\Wild-Pako\Desktop\PlanetSide 2 PSG.lnk
2013-10-12 17:07 - 2013-10-12 17:07 - 00000810 _____ C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlanetSide 2 PSG.lnk
2013-10-10 19:02 - 2013-10-10 19:02 - 00001084 _____ C:\Users\Public\Desktop\Need for Speed Most Wanted.lnk
2013-10-09 21:53 - 2013-10-09 21:54 - 00000000 ____D C:\Users\Wild-Pako\Documents\NFSTR
2013-10-09 18:24 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-09 18:24 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-09 18:24 - 2013-09-23 01:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-10-09 18:24 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-09 18:24 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-09 18:24 - 2013-09-23 00:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-10-09 18:24 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-09 18:24 - 2013-09-23 00:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-10-09 18:24 - 2013-09-21 05:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-09 18:24 - 2013-09-21 05:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-09 18:24 - 2013-09-21 04:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-10-09 18:24 - 2013-09-21 04:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-10-09 18:03 - 2013-09-04 14:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-09 18:03 - 2013-09-04 14:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-09 18:03 - 2013-09-04 14:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-09 18:03 - 2013-09-04 14:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-09 18:03 - 2013-09-04 14:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-10-09 18:03 - 2013-09-04 14:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-10-09 18:03 - 2013-09-04 14:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-09 18:03 - 2013-08-28 03:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-09 18:03 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-09 18:03 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-09 18:03 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-09 18:03 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-09 18:03 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-09 18:03 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-09 18:03 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-09 18:03 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-09 18:03 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-09 18:03 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-10-09 18:03 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-10-09 18:03 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-10-09 18:03 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-09 18:03 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2013-10-09 18:03 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2013-10-09 18:03 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2013-10-09 18:03 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-09 18:03 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-09 18:03 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-08 21:32 - 2013-10-08 21:32 - 00001374 _____ C:\Users\Wild-Pako\Desktop\farcry3.lnk
2013-10-08 21:32 - 2013-10-08 21:32 - 00000000 ____D C:\Users\Wild-Pako\Documents\My Games
2013-10-08 21:32 - 2013-10-08 21:32 - 00000000 ____D C:\ProgramData\Orbit
2013-10-08 20:39 - 2013-10-08 20:39 - 00001513 _____ C:\Users\Wild-Pako\Desktop\Need For Speed The Run.lnk
2013-10-08 19:58 - 2013-10-14 18:57 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-10-08 19:58 - 2013-10-08 19:58 - 00001922 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-10-08 19:58 - 2013-08-30 09:48 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-10-08 19:58 - 2013-08-30 09:48 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-10-08 19:58 - 2013-08-30 09:48 - 00204880 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-10-08 19:58 - 2013-08-30 09:48 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-10-08 19:58 - 2013-08-30 09:48 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2013-10-08 19:58 - 2013-08-30 09:48 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-10-08 19:58 - 2013-08-30 09:48 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2013-10-08 19:58 - 2013-08-30 09:48 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys
2013-10-08 19:58 - 2013-08-30 09:47 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-10-08 19:56 - 2013-10-08 19:56 - 00000000 ____D C:\Program Files\AVAST Software
2013-10-08 19:56 - 2013-08-30 09:47 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-10-08 19:52 - 2013-10-08 19:56 - 00000000 ____D C:\ProgramData\AVAST Software
2013-10-08 19:08 - 2013-10-08 19:08 - 00000000 ____D C:\ProgramData\Futuremark
2013-10-08 19:07 - 2013-10-08 19:07 - 00000924 _____ C:\Users\Public\Desktop\3DMark Vantage.lnk
2013-10-08 19:06 - 2013-10-08 19:06 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-10-08 19:06 - 2013-10-08 19:06 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-10-07 21:57 - 2013-10-07 21:57 - 00007601 _____ C:\Users\Wild-Pako\AppData\Local\Resmon.ResmonCfg
2013-10-07 21:38 - 2013-10-07 21:59 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-10-07 21:38 - 2013-10-07 21:39 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-10-07 21:38 - 2013-10-07 21:38 - 00001343 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-10-07 21:38 - 2013-10-07 21:38 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-10-07 21:38 - 2009-01-25 13:14 - 00017272 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2013-10-07 19:10 - 2013-10-07 19:10 - 00000000 ____D C:\ProgramData\ATI
2013-10-07 18:58 - 2013-10-07 18:58 - 00055617 _____ C:\Windows\SysWOW64\CCCInstall_201310071858030463.log
2013-10-07 18:58 - 2013-10-07 18:58 - 00000000 ____D C:\ProgramData\AMD
2013-10-07 18:58 - 2013-10-07 18:58 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2013-10-07 18:56 - 2013-10-07 18:56 - 00018620 _____ C:\Windows\SysWOW64\CCCInstall_201310071856358562.log
2013-10-07 18:55 - 2013-10-07 18:55 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2013-10-07 18:52 - 2013-10-07 18:53 - 00000000 ____D C:\ProgramData\Package Cache
2013-10-06 23:20 - 2013-10-06 23:20 - 00000045 _____ C:\Users\Wild-Pako\Desktop\Neues Textdokument.txt
2013-10-03 18:20 - 2013-10-03 18:26 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
2013-10-03 15:26 - 2008-09-24 10:38 - 01048576 _____ C:\Users\Wild-Pako\ep43ds3.f9
2013-10-03 15:26 - 2008-08-28 09:16 - 00026351 _____ C:\Users\Wild-Pako\FLASHSPI.EXE
2013-10-03 13:51 - 2013-10-03 14:47 - 00037130 _____ C:\pingstat.txt
2013-10-03 13:49 - 2013-10-03 13:50 - 00000332 _____ C:\Users\Wild-Pako\Desktop\Neues Textdokument.bat
2013-10-03 10:26 - 2013-10-03 10:26 - 00001160 _____ C:\Users\Wild-Pako\Desktop\launcher - Verknüpfung.lnk
2013-10-02 23:03 - 2013-10-02 23:03 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Sinvise Systems
2013-10-02 23:03 - 2013-10-02 23:03 - 00000000 ____D C:\Program Files (x86)\Sinvise Systems
2013-10-02 21:26 - 2013-10-02 21:27 - 00000000 ____D C:\Users\Wild-Pako\Documents\NFS Undercover
2013-10-02 21:24 - 2013-10-02 21:24 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Leadertech
2013-10-02 21:06 - 2013-10-10 19:08 - 00000000 ____D C:\Users\Wild-Pako\Documents\Criterion Games
2013-10-02 21:06 - 2013-10-02 21:06 - 00000000 ____D C:\ProgramData\Electronic Arts
2013-10-02 21:06 - 2013-10-02 21:06 - 00000000 ____D C:\ProgramData\EA Core
2013-10-01 12:42 - 2013-10-07 22:10 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\CrossLoop
2013-09-29 14:07 - 2013-10-11 19:53 - 00000000 ____D C:\Windows\Minidump
2013-09-29 13:45 - 2013-09-29 13:48 - 00000000 ____D C:\Users\Wild-Pako\Desktop\Prime95
2013-09-29 13:43 - 2013-09-29 13:43 - 00000948 _____ C:\Users\Wild-Pako\Desktop\Core Temp.lnk
2013-09-29 11:43 - 2013-09-29 11:43 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-09-29 11:39 - 2013-10-03 10:23 - 00000000 ____D C:\Users\Wild-Pako\Documents\PhoenixRC
2013-09-29 11:35 - 2013-10-03 10:25 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhoenixRC
2013-09-28 22:33 - 2013-10-14 19:05 - 00001286 _____ C:\Windows\Tasks\Feven 1.5-updater.job
2013-09-28 22:33 - 2013-10-14 19:05 - 00001190 _____ C:\Windows\Tasks\Feven 1.5-codedownloader.job
2013-09-28 22:33 - 2013-10-14 19:05 - 00001090 _____ C:\Windows\Tasks\Feven 1.5-enabler.job
2013-09-28 22:33 - 2013-09-28 22:33 - 00004316 _____ C:\Windows\System32\Tasks\Feven 1.5-updater
2013-09-28 22:33 - 2013-09-28 22:33 - 00004220 _____ C:\Windows\System32\Tasks\Feven 1.5-codedownloader
2013-09-28 22:33 - 2013-09-28 22:33 - 00004120 _____ C:\Windows\System32\Tasks\Feven 1.5-enabler
2013-09-28 22:32 - 2013-10-14 19:05 - 00001818 _____ C:\Windows\Tasks\Feven 1.5-firefoxinstaller.job
2013-09-28 22:32 - 2013-09-28 22:32 - 00000869 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2013-09-28 22:32 - 2013-09-28 22:32 - 00000000 ____D C:\Program Files\CPUID
2013-09-28 22:31 - 2013-10-14 19:05 - 00001894 _____ C:\Windows\Tasks\Feven 1.5-chromeinstaller.job
2013-09-28 22:31 - 2013-09-28 22:33 - 00000000 ____D C:\Program Files (x86)\Feven 1.5
2013-09-28 22:12 - 2013-09-28 22:12 - 00000000 ____D C:\Program Files\Defraggler
2013-09-28 22:11 - 2013-09-28 22:11 - 03084304 _____ (Piriform Ltd) C:\Users\Wild-Pako\Downloads\dfsetup215742_slim.exe
2013-09-28 22:11 - 2013-09-28 22:11 - 03084304 _____ (Piriform Ltd) C:\Users\Wild-Pako\Downloads\dfsetup215742_slim (1).exe
2013-09-28 22:07 - 2013-09-28 22:07 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\avgchrome
2013-09-28 21:41 - 2013-09-28 21:41 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\2K Games
2013-09-28 21:39 - 2013-09-28 21:39 - 00000902 _____ C:\Users\Wild-Pako\Desktop\SteamLess Mafia II.lnk
2013-09-28 21:39 - 2013-09-28 21:39 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steamless Mafia II Pack
2013-09-28 18:04 - 2013-10-09 18:26 - 01593956 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-09-28 13:51 - 2013-09-28 13:51 - 00001964 _____ C:\Users\Public\Desktop\FileZilla Client.lnk
2013-09-28 13:51 - 2013-09-28 13:51 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2013-09-27 23:09 - 2013-09-27 23:09 - 00000000 ____D C:\Users\Wild-Pako\Documents\Rockstar Games
2013-09-27 23:05 - 2013-09-27 23:05 - 00000000 __SHD C:\ProgramData\SecuROM
2013-09-27 23:05 - 2013-09-27 23:05 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Rockstar Games
2013-09-27 22:54 - 2013-09-27 22:54 - 00000000 ____D C:\Windows\SysWOW64\xlive
2013-09-27 22:54 - 2013-09-27 22:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2013-09-27 22:53 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
2013-09-27 22:53 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2013-09-27 22:53 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
2013-09-27 22:53 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2013-09-27 22:53 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2013-09-27 22:53 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2013-09-27 22:53 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2013-09-27 22:53 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2013-09-27 22:53 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2013-09-27 22:53 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2013-09-27 22:53 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2013-09-27 22:53 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2013-09-27 22:53 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2013-09-27 22:53 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2013-09-27 22:53 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
2013-09-27 22:53 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2013-09-27 22:53 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
2013-09-27 22:53 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2013-09-27 22:53 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2013-09-27 22:53 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2013-09-27 22:53 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
2013-09-27 22:53 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2013-09-27 22:53 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2013-09-27 22:53 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2013-09-27 22:53 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2013-09-27 22:53 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2013-09-27 22:53 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2013-09-27 22:53 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2013-09-27 22:53 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2013-09-27 22:53 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2013-09-27 22:53 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2013-09-27 22:53 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
2013-09-27 22:53 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
2013-09-27 22:53 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2013-09-27 22:53 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2013-09-27 22:53 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
2013-09-27 22:53 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2013-09-27 22:53 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
2013-09-27 22:53 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2013-09-27 22:53 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll
2013-09-27 22:53 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2013-09-27 22:53 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll
2013-09-27 22:53 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2013-09-27 22:53 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
2013-09-27 22:53 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2013-09-27 22:53 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2013-09-27 22:53 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2013-09-27 22:53 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
2013-09-27 22:53 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2013-09-27 22:53 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
2013-09-27 22:53 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2013-09-27 22:53 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2013-09-27 22:53 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2013-09-27 22:53 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2013-09-27 22:53 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2013-09-27 22:53 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2013-09-27 22:53 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2013-09-27 22:53 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2013-09-27 22:53 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2013-09-27 22:53 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
2013-09-27 22:53 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2013-09-27 22:53 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
2013-09-27 22:53 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2013-09-27 22:53 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2013-09-27 22:53 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2013-09-27 22:53 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2013-09-27 22:53 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2013-09-27 22:53 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2013-09-27 22:53 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2013-09-27 22:53 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
2013-09-27 22:53 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
2013-09-27 22:53 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2013-09-27 22:53 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2013-09-27 22:53 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
2013-09-27 22:53 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
2013-09-27 22:53 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2013-09-27 22:53 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2013-09-27 22:53 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2013-09-27 22:53 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2013-09-27 22:53 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
2013-09-27 22:53 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2013-09-27 22:53 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
2013-09-27 22:53 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2013-09-27 22:53 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
2013-09-27 22:53 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
2013-09-27 22:53 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2013-09-27 22:53 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2013-09-27 22:53 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
2013-09-27 22:53 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2013-09-27 22:53 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
2013-09-27 22:53 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2013-09-27 22:53 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
2013-09-27 22:53 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2013-09-27 22:53 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
2013-09-27 22:53 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2013-09-27 22:53 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
2013-09-27 22:53 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2013-09-27 22:53 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
2013-09-27 22:53 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2013-09-27 22:53 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
2013-09-27 22:53 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2013-09-27 22:53 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
2013-09-27 22:53 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2013-09-27 22:53 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
2013-09-27 22:53 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2013-09-27 22:53 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
2013-09-27 22:53 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2013-09-27 22:53 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2013-09-27 22:53 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2013-09-27 22:53 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
2013-09-27 22:53 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2013-09-27 22:53 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
2013-09-27 22:53 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2013-09-27 22:53 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
2013-09-27 22:53 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2013-09-27 22:53 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2013-09-27 22:53 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2013-09-27 22:53 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
2013-09-27 22:53 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2013-09-27 22:53 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
2013-09-27 22:53 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2013-09-27 22:53 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
2013-09-27 22:53 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2013-09-27 22:53 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2013-09-27 22:53 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2013-09-27 22:53 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2013-09-27 22:53 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2013-09-27 22:53 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2013-09-27 22:53 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2013-09-27 22:53 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2013-09-27 22:53 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2013-09-27 22:53 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
2013-09-27 22:53 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2013-09-27 22:53 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2013-09-27 22:53 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2013-09-27 22:53 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2013-09-27 22:52 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2013-09-27 22:52 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2013-09-27 22:52 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2013-09-27 22:52 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2013-09-27 22:52 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2013-09-27 22:52 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2013-09-27 22:52 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2013-09-27 22:52 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2013-09-27 22:52 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2013-09-27 22:52 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2013-09-27 22:52 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2013-09-27 22:52 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2013-09-27 22:52 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2013-09-27 22:52 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2013-09-27 22:52 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2013-09-27 22:52 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2013-09-27 22:52 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2013-09-27 22:52 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2013-09-27 22:52 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2013-09-27 22:52 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2013-09-27 22:52 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2013-09-27 22:52 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2013-09-27 22:52 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2013-09-27 22:52 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2013-09-27 22:52 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2013-09-27 22:52 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2013-09-27 22:52 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2013-09-27 22:52 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2013-09-27 22:52 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2013-09-27 22:52 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2013-09-27 22:52 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2013-09-27 22:52 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2013-09-27 22:51 - 2013-09-27 22:51 - 00001045 _____ C:\Users\Public\Desktop\Grand Theft Auto IV Complete Edition.lnk
2013-09-27 17:14 - 2013-09-27 17:18 - 00000000 ____D C:\tempvideo
2013-09-27 17:13 - 2013-09-27 23:05 - 00000044 _____ C:\DebugTraceAP.log
2013-09-27 12:43 - 2013-09-27 12:45 - 00000000 ____D C:\Program Files (x86)\DU Meter
2013-09-27 12:43 - 2013-09-27 12:43 - 00000000 ____D C:\ProgramData\Hagel Technologies
2013-09-27 12:23 - 2013-09-27 12:23 - 00001047 _____ C:\Users\Wild-Pako\Desktop\Dropbox.lnk
2013-09-27 12:21 - 2013-09-27 12:21 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-09-27 12:20 - 2013-10-14 19:06 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Dropbox
2013-09-27 11:48 - 2013-09-27 11:48 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Miranda IM
2013-09-27 08:22 - 2013-09-27 08:22 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\OpenOffice
2013-09-27 08:19 - 2013-09-27 08:19 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk
2013-09-27 08:18 - 2013-09-27 08:19 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-09-26 20:17 - 2013-10-03 04:52 - 00001050 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk
2013-09-26 20:17 - 2013-09-26 20:17 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2013-09-26 15:00 - 2013-09-26 15:00 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-09-26 15:00 - 2013-09-26 15:00 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-09-26 07:52 - 2013-10-14 19:05 - 00009930 _____ C:\Windows\setupact.log
2013-09-26 07:52 - 2013-09-26 07:52 - 00000000 _____ C:\Windows\setuperr.log
2013-09-25 22:15 - 2013-09-25 22:15 - 00000783 _____ C:\Users\Wild-Pako\Desktop\! - - Transfer - - !.lnk
2013-09-25 21:57 - 2013-09-25 21:57 - 00000000 ____D C:\ProgramData\Canneverbe Limited
2013-09-25 21:56 - 2013-09-25 21:56 - 00001913 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk
2013-09-25 21:56 - 2013-09-25 21:56 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Canneverbe Limited
2013-09-25 21:56 - 2013-09-25 21:56 - 00000000 ____D C:\Program Files (x86)\CDBurnerXP
2013-09-25 21:51 - 2013-09-25 21:51 - 00001501 _____ C:\Users\Wild-Pako\Desktop\Load.lnk
2013-09-25 21:34 - 2013-09-25 21:34 - 00001282 _____ C:\Users\Public\Desktop\EL3K My ELAS Remote Programmer.lnk
2013-09-25 21:34 - 2013-09-25 21:34 - 00000000 ____D C:\Program Files (x86)\Electronics Line
2013-09-25 20:41 - 2013-09-25 20:41 - 00002050 _____ C:\Users\Wild-Pako\Desktop\JDownloader.lnk
2013-09-25 20:40 - 2013-09-25 20:40 - 00000000 ____D C:\Users\Wild-Pako\Programme
2013-09-25 20:29 - 2013-09-25 20:31 - 00000000 ____D C:\Windows\rescache
2013-09-25 19:58 - 2013-09-25 19:59 - 175636928 _____ C:\Users\Wild-Pako\Downloads\130254498000.rar.part
2013-09-25 19:40 - 2013-10-14 18:53 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-25 19:40 - 2013-10-10 18:48 - 00004112 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-09-25 19:40 - 2013-10-10 18:48 - 00003860 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-09-25 19:40 - 2013-10-08 00:48 - 00002143 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-09-25 19:39 - 2013-10-14 19:05 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-25 19:39 - 2013-10-04 22:11 - 00001702 _____ C:\Users\Wild-Pako\Desktop\MPC-HC x64.lnk
2013-09-25 19:39 - 2013-10-04 22:11 - 00000000 ____D C:\Program Files\MPC-HC
2013-09-25 19:39 - 2013-09-25 19:40 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Google
2013-09-25 19:39 - 2013-09-25 19:40 - 00000000 ____D C:\Program Files (x86)\Google
2013-09-25 19:39 - 2013-09-25 19:39 - 00784872 _____ (Google Inc.) C:\Users\Wild-Pako\Downloads\ChromeSetup.exe
2013-09-25 19:38 - 2013-09-25 19:38 - 07990240 _____ (MPC-HC Team                                                 ) C:\Users\Wild-Pako\Downloads\MPC-HC.1.6.8.x64.exe
2013-09-25 19:38 - 2013-09-25 19:38 - 00001030 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-09-25 19:37 - 2013-09-25 19:37 - 23003252 _____ C:\Users\Wild-Pako\Downloads\vlc-2.0.8-win32.exe
2013-09-25 19:07 - 2013-10-09 18:23 - 00000000 ____D C:\Windows\system32\MRT
2013-09-25 18:00 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-09-25 18:00 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-09-25 18:00 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-09-25 18:00 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-09-25 18:00 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-09-25 18:00 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-09-25 18:00 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-09-25 18:00 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-09-25 18:00 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-09-25 18:00 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-09-25 18:00 - 2013-04-12 16:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2013-09-25 18:00 - 2013-04-10 08:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2013-09-25 18:00 - 2011-02-03 13:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2013-09-25 17:59 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-09-25 17:59 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-09-25 17:59 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-09-25 17:59 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-09-25 17:59 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-09-25 17:59 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-25 17:59 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-09-25 17:59 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-25 17:59 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-09-25 17:59 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-09-25 17:59 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-09-25 17:59 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-09-25 17:59 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-09-25 17:59 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-25 17:59 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-09-25 17:59 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-09-25 17:59 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-09-25 17:59 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-09-25 17:59 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-09-25 17:59 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-25 17:59 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-09-25 17:43 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-25 17:43 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-25 17:43 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-25 17:43 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-09-25 17:43 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-09-25 17:43 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-09-25 17:43 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-09-25 17:43 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-09-25 17:43 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-09-25 17:43 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-09-25 17:43 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-09-25 17:43 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-09-25 17:43 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-09-25 17:43 - 2013-05-13 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2013-09-25 17:43 - 2013-05-13 05:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2013-09-25 17:43 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-09-25 17:43 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-09-25 17:43 - 2013-05-10 07:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2013-09-25 17:43 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-09-25 17:43 - 2013-04-26 07:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-09-25 17:43 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-09-25 17:43 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-09-25 17:43 - 2013-04-17 09:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-09-25 17:43 - 2013-04-17 08:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2013-09-25 17:43 - 2013-04-01 00:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2013-09-25 17:43 - 2013-03-19 07:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2013-09-25 17:43 - 2013-03-19 07:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2013-09-25 17:43 - 2013-02-27 08:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2013-09-25 17:43 - 2013-02-27 07:48 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-09-25 17:43 - 2013-02-27 07:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2013-09-25 17:43 - 2013-02-27 06:49 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-09-25 17:38 - 2013-09-25 17:38 - 00000000 ____D C:\ProgramData\Oracle
2013-09-25 17:38 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-09-25 17:38 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-09-25 17:37 - 2013-09-25 17:36 - 00868264 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-09-25 17:37 - 2013-09-25 17:36 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-09-25 17:37 - 2013-09-25 17:36 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-09-25 17:37 - 2013-09-25 17:36 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-09-25 17:37 - 2013-09-25 17:36 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-09-25 17:20 - 2013-09-25 17:20 - 02564703 _____ C:\Users\Wild-Pako\Downloads\CMI8738_WDM_0639XP.zip
2013-09-25 17:02 - 2012-07-26 06:55 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2013-09-25 17:02 - 2012-07-26 04:36 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2013-09-25 17:02 - 2012-06-02 16:35 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2013-09-25 16:56 - 2013-09-25 16:56 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-09-25 16:56 - 2013-09-25 16:56 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-09-25 16:56 - 2013-09-25 16:56 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-09-25 16:56 - 2013-09-25 16:56 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-09-25 16:56 - 2013-09-25 16:56 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-09-25 16:56 - 2013-09-25 16:56 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-09-25 16:56 - 2013-09-25 16:56 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-09-25 16:56 - 2013-09-25 16:56 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-09-25 16:56 - 2013-09-25 16:56 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-09-25 16:55 - 2013-09-25 17:02 - 00008799 _____ C:\Windows\IE10_main.log
2013-09-25 16:54 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2013-09-25 16:54 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2013-09-25 16:54 - 2012-08-23 16:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2013-09-25 16:54 - 2012-08-23 15:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2013-09-25 16:54 - 2012-08-23 15:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2013-09-25 16:54 - 2012-08-23 15:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-09-25 16:54 - 2012-08-23 15:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-09-25 16:54 - 2012-08-23 15:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2013-09-25 16:54 - 2012-08-23 15:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2013-09-25 16:54 - 2012-08-23 15:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-09-25 16:54 - 2012-08-23 15:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2013-09-25 16:54 - 2012-08-23 15:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-09-25 16:54 - 2012-08-23 14:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2013-09-25 16:54 - 2012-08-23 13:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2013-09-25 16:54 - 2012-08-23 13:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-09-25 16:54 - 2012-08-23 13:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2013-09-25 16:54 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2013-09-25 16:54 - 2012-08-23 12:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2013-09-25 16:54 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2013-09-25 16:54 - 2012-08-23 12:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
         

Alt 14.10.2013, 19:24   #11
Wild-Pako
 
Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome - Standard

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome



Code:
ATTFilter
2013-09-25 16:54 - 2012-08-23 12:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2013-09-25 16:54 - 2012-08-23 11:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2013-09-25 16:54 - 2012-08-23 10:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-09-25 16:54 - 2012-08-23 10:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2013-09-25 16:51 - 2012-07-26 05:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2013-09-25 16:51 - 2012-07-26 05:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2013-09-25 16:51 - 2012-07-26 05:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2013-09-25 16:51 - 2012-07-26 05:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2013-09-25 16:51 - 2012-07-26 05:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2013-09-25 16:51 - 2012-07-26 04:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2013-09-25 16:51 - 2012-07-26 04:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2013-09-25 16:51 - 2012-06-02 16:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2013-09-25 16:48 - 2013-01-13 23:17 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 23:17 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 23:16 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 23:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-09-25 16:48 - 2013-01-13 23:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-09-25 16:48 - 2013-01-13 23:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 23:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 23:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 23:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:35 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:35 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:35 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-09-25 16:48 - 2013-01-13 22:22 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-09-25 16:48 - 2013-01-13 22:20 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2013-09-25 16:48 - 2013-01-13 22:09 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2013-09-25 16:48 - 2013-01-13 22:08 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2013-09-25 16:48 - 2013-01-13 21:58 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-09-25 16:48 - 2013-01-13 21:54 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-09-25 16:48 - 2013-01-13 21:53 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2013-09-25 16:48 - 2013-01-13 21:53 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2013-09-25 16:48 - 2013-01-13 21:51 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-09-25 16:48 - 2013-01-13 21:49 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2013-09-25 16:48 - 2013-01-13 21:48 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2013-09-25 16:48 - 2013-01-13 21:46 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2013-09-25 16:48 - 2013-01-13 21:38 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-09-25 16:48 - 2013-01-13 21:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-09-25 16:48 - 2013-01-13 21:37 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-09-25 16:48 - 2013-01-13 21:25 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2013-09-25 16:48 - 2013-01-13 21:24 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-09-25 16:48 - 2013-01-13 21:24 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2013-09-25 16:48 - 2013-01-13 21:20 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-09-25 16:48 - 2013-01-13 21:20 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-09-25 16:48 - 2013-01-13 21:10 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-09-25 16:48 - 2013-01-13 21:02 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-09-25 16:48 - 2013-01-13 20:34 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-09-25 16:48 - 2013-01-13 20:32 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-09-25 16:48 - 2013-01-13 20:09 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-09-25 16:48 - 2013-01-13 19:26 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2013-09-25 16:48 - 2013-01-13 19:05 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2013-09-25 16:48 - 2013-01-04 08:11 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2013-09-25 16:48 - 2013-01-04 08:11 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2013-09-25 16:46 - 2013-01-24 08:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2013-09-25 16:46 - 2012-12-07 15:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2013-09-25 16:46 - 2012-12-07 15:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2013-09-25 16:46 - 2012-12-07 14:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2013-09-25 16:46 - 2012-12-07 14:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2013-09-25 16:46 - 2012-12-07 13:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2013-09-25 16:46 - 2012-12-07 13:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2013-09-25 16:46 - 2012-12-07 13:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2013-09-25 16:46 - 2012-12-07 13:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2013-09-25 16:46 - 2012-12-07 13:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2013-09-25 16:46 - 2012-12-07 13:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2013-09-25 16:46 - 2012-12-07 13:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2013-09-25 16:46 - 2012-12-07 13:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2013-09-25 16:46 - 2012-12-07 13:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2013-09-25 16:46 - 2012-12-07 13:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2013-09-25 16:46 - 2012-12-07 13:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2013-09-25 16:46 - 2012-12-07 13:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2013-09-25 16:46 - 2012-12-07 13:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2013-09-25 16:46 - 2012-12-07 13:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs
2013-09-25 16:46 - 2012-12-07 12:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs
2013-09-25 16:46 - 2012-11-30 01:17 - 00420064 _____ C:\Windows\SysWOW64\locale.nls
2013-09-25 16:46 - 2012-11-30 01:15 - 00420064 _____ C:\Windows\system32\locale.nls
2013-09-25 16:46 - 2012-11-22 07:44 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2013-09-25 16:46 - 2012-11-22 06:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2013-09-25 16:46 - 2012-10-09 20:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2013-09-25 16:46 - 2012-10-09 20:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2013-09-25 16:46 - 2012-10-09 19:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2013-09-25 16:46 - 2012-10-09 19:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2013-09-25 16:46 - 2012-10-03 19:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2013-09-25 16:46 - 2012-10-03 19:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2013-09-25 16:46 - 2012-10-03 19:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2013-09-25 16:46 - 2012-10-03 19:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2013-09-25 16:46 - 2012-10-03 19:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2013-09-25 16:46 - 2012-10-03 19:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2013-09-25 16:46 - 2012-10-03 18:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
2013-09-25 16:46 - 2012-10-03 18:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2013-09-25 16:46 - 2012-10-03 18:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
2013-09-25 16:46 - 2012-10-03 18:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2013-09-25 16:46 - 2012-08-24 20:13 - 00154480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-09-25 16:46 - 2012-08-24 20:09 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-09-25 16:46 - 2012-08-24 20:05 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-09-25 16:46 - 2012-08-24 20:03 - 01448448 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-09-25 16:46 - 2012-08-24 18:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-09-25 16:46 - 2012-08-24 18:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-09-25 16:46 - 2012-08-24 18:53 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-09-25 16:46 - 2012-08-22 20:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2013-09-25 16:46 - 2012-08-21 23:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
2013-09-25 16:46 - 2012-07-04 22:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
2013-09-25 16:46 - 2012-05-05 10:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2013-09-25 16:46 - 2012-05-05 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2013-09-25 16:46 - 2012-05-04 13:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2013-09-25 16:46 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2013-09-25 16:46 - 2012-01-13 09:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2013-09-25 16:42 - 2012-02-11 08:36 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2013-09-25 16:42 - 2012-02-11 08:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
2013-09-25 16:42 - 2011-05-04 07:25 - 02315776 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2013-09-25 16:42 - 2011-05-04 07:22 - 02223616 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2013-09-25 16:42 - 2011-05-04 07:22 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2013-09-25 16:42 - 2011-05-04 07:22 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2013-09-25 16:42 - 2011-05-04 07:22 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2013-09-25 16:42 - 2011-05-04 07:22 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2013-09-25 16:42 - 2011-05-04 07:19 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2013-09-25 16:42 - 2011-05-04 07:19 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2013-09-25 16:42 - 2011-05-04 07:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2013-09-25 16:42 - 2011-05-04 06:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2013-09-25 16:42 - 2011-05-04 06:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2013-09-25 16:42 - 2011-05-04 06:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2013-09-25 16:42 - 2011-05-04 06:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2013-09-25 16:42 - 2011-05-04 06:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2013-09-25 16:42 - 2011-05-04 06:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2013-09-25 16:42 - 2011-05-04 06:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2013-09-25 16:42 - 2011-05-04 06:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2013-09-25 16:42 - 2011-05-04 06:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2013-09-25 16:39 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2013-09-25 16:39 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2013-09-25 16:38 - 2013-09-25 16:38 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in
2013-09-25 16:38 - 2013-09-25 16:38 - 00000000 ____D C:\Program Files (x86)\Winamp Detect
2013-09-25 16:37 - 2013-09-25 16:37 - 13385888 _____ (Nullsoft, Inc.) C:\Users\Wild-Pako\Downloads\winamp565_full_emusic-7plus_de-de.exe
2013-09-24 19:15 - 2013-09-25 16:39 - 00000943 _____ C:\Users\Public\Desktop\Winamp.lnk
2013-09-24 19:14 - 2013-09-25 17:22 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Winamp
2013-09-24 19:14 - 2013-09-25 16:39 - 00000000 ____D C:\Program Files (x86)\Winamp
2013-09-24 19:14 - 2011-03-04 21:44 - 02095600 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxsfs.dll
2013-09-24 19:14 - 2011-03-04 21:44 - 00698864 ____N (Sonic Solutions) C:\Windows\SysWOW64\px.dll
2013-09-24 19:14 - 2011-03-04 21:44 - 00571888 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxdrv.dll
2013-09-24 19:14 - 2011-03-04 21:44 - 00440816 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxwave.dll
2013-09-24 19:14 - 2011-03-04 21:44 - 00219632 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxmas.dll
2013-09-24 19:14 - 2011-03-04 21:44 - 00133616 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxafs.dll
2013-09-24 19:14 - 2011-03-04 21:44 - 00100848 ____N (Sonic Solutions) C:\Windows\SysWOW64\vxblock.dll
2013-09-24 19:14 - 2011-03-04 21:44 - 00072176 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxhpinst.exe
2013-09-24 19:14 - 2011-03-04 21:44 - 00068592 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxinsa64.exe
2013-09-24 19:14 - 2011-03-04 21:44 - 00068080 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxcpya64.exe
2013-09-22 18:16 - 2013-09-27 08:11 - 00000000 ____D C:\Windows\system32\appmgmt
2013-09-22 18:11 - 2013-09-22 18:11 - 00003196 _____ C:\Windows\System32\Tasks\{758CECE7-FCF0-43F8-9FAD-6E45BC86DE8D}
2013-09-20 19:52 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2013-09-20 19:52 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2013-09-20 19:49 - 2013-09-20 19:54 - 00466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2013-09-20 19:49 - 2013-09-20 19:54 - 00444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2013-09-20 19:49 - 2013-09-20 19:54 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2013-09-20 19:49 - 2013-09-20 19:54 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2013-09-20 19:49 - 2013-09-20 19:54 - 00000628 _____ C:\Users\Public\Desktop\3DMark06.lnk
2013-09-20 19:49 - 2013-09-20 19:49 - 00000000 ____D C:\Program Files (x86)\OpenAL
2013-09-20 19:47 - 2013-09-20 19:47 - 00000000 ____D C:\Program Files (x86)\Futuremark
2013-09-20 19:44 - 2013-09-20 19:44 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\ATI
2013-09-20 19:44 - 2013-09-20 19:44 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\ATI
2013-09-20 19:43 - 2013-09-20 19:43 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2013-09-18 19:40 - 2013-09-18 19:40 - 00000000 _____ C:\Windows\ativpsrm.bin
2013-09-18 19:39 - 2013-09-18 19:39 - 00000000 ____D C:\Program Files (x86)\AMD APP
2013-09-18 19:38 - 2013-10-07 18:57 - 00000000 ____D C:\Program Files\ATI Technologies
2013-09-18 19:38 - 2013-09-18 19:38 - 00000000 ____D C:\Program Files\ATI

==================== One Month Modified Files and Folders =======

2013-10-14 19:14 - 2013-10-14 19:14 - 00001254 _____ C:\Users\Wild-Pako\Desktop\JRT.txt
2013-10-14 19:10 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-14 19:10 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-14 19:08 - 2013-10-14 19:08 - 00000000 ____D C:\Windows\ERUNT
2013-10-14 19:06 - 2013-09-27 12:20 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Dropbox
2013-10-14 19:05 - 2013-09-28 22:33 - 00001286 _____ C:\Windows\Tasks\Feven 1.5-updater.job
2013-10-14 19:05 - 2013-09-28 22:33 - 00001190 _____ C:\Windows\Tasks\Feven 1.5-codedownloader.job
2013-10-14 19:05 - 2013-09-28 22:33 - 00001090 _____ C:\Windows\Tasks\Feven 1.5-enabler.job
2013-10-14 19:05 - 2013-09-28 22:32 - 00001818 _____ C:\Windows\Tasks\Feven 1.5-firefoxinstaller.job
2013-10-14 19:05 - 2013-09-28 22:31 - 00001894 _____ C:\Windows\Tasks\Feven 1.5-chromeinstaller.job
2013-10-14 19:05 - 2013-09-26 07:52 - 00009930 _____ C:\Windows\setupact.log
2013-10-14 19:05 - 2013-09-25 19:39 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-14 19:05 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-14 19:04 - 2009-08-13 17:15 - 01333441 _____ C:\Windows\WindowsUpdate.log
2013-10-14 19:03 - 2013-10-12 19:48 - 00000000 ____D C:\AdwCleaner
2013-10-14 19:01 - 2013-10-14 19:01 - 01032220 _____ (Thisisu) C:\Users\Wild-Pako\Desktop\JRT.exe
2013-10-14 19:00 - 2013-10-14 19:00 - 01048960 _____ C:\Users\Wild-Pako\Desktop\adwcleaner(1).exe
2013-10-14 18:57 - 2013-10-08 19:58 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-10-14 18:56 - 2009-08-13 22:36 - 00196706 _____ C:\Windows\PFRO.log
2013-10-14 18:53 - 2013-09-25 19:40 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-14 18:49 - 2013-10-14 18:49 - 00001073 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-10-14 18:49 - 2013-10-14 18:49 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Malwarebytes
2013-10-14 18:49 - 2013-10-14 18:49 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-14 18:49 - 2013-10-14 18:49 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-14 10:38 - 2012-07-31 20:20 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-13 17:20 - 2013-10-13 17:14 - 00000592 _____ C:\Users\Wild-Pako\ashot.log
2013-10-13 17:14 - 2013-10-13 17:14 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\mightypocket
2013-10-13 17:14 - 2009-08-13 17:20 - 00000000 ____D C:\Users\Wild-Pako
2013-10-13 17:13 - 2013-10-13 17:13 - 00000000 ____D C:\Program Files (x86)\Android Screen Capture
2013-10-13 17:09 - 2013-10-13 17:09 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2013-10-13 17:08 - 2013-10-13 17:08 - 00000000 ____D C:\Users\Wild-Pako\.android
2013-10-13 17:07 - 2013-10-13 17:07 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\MyPhoneExplorer
2013-10-13 17:07 - 2013-10-13 17:07 - 00000000 ____D C:\Program Files (x86)\MyPhoneExplorer
2013-10-13 17:02 - 2013-10-13 17:02 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log
2013-10-13 17:02 - 2013-10-13 17:02 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-10-13 17:01 - 2013-10-13 17:01 - 00000000 ____D C:\Users\Wild-Pako\Documents\samsung
2013-10-13 17:01 - 2013-10-13 17:01 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Samsung
2013-10-13 17:01 - 2013-10-13 17:01 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Samsung
2013-10-13 17:01 - 2013-10-13 16:59 - 00000000 ____D C:\ProgramData\Samsung
2013-10-13 17:00 - 2009-08-13 17:34 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-13 16:58 - 2013-10-13 16:58 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Downloaded Installations
2013-10-13 16:58 - 2009-07-26 14:25 - 00699416 _____ C:\Windows\system32\perfh007.dat
2013-10-13 16:58 - 2009-07-26 14:25 - 00149556 _____ C:\Windows\system32\perfc007.dat
2013-10-13 16:58 - 2009-07-14 07:13 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-13 15:26 - 2013-10-13 15:26 - 00035713 _____ C:\ComboFix.txt
2013-10-13 15:26 - 2013-10-13 15:14 - 00000000 ____D C:\Qoobox
2013-10-13 15:26 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-10-13 15:25 - 2013-10-13 15:13 - 00000000 ____D C:\Windows\erdnt
2013-10-13 15:24 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-10-13 15:13 - 2013-10-13 15:13 - 05132083 ____R (Swearware) C:\Users\Wild-Pako\Desktop\ComboFix.exe
2013-10-13 11:15 - 2013-10-13 11:15 - 00000971 _____ C:\Users\Wild-Pako\Desktop\TransMac.lnk
2013-10-13 11:15 - 2013-10-13 11:15 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TransMac
2013-10-13 11:15 - 2013-10-13 11:15 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\TransMac
2013-10-13 11:15 - 2013-10-13 11:15 - 00000000 ____D C:\Program Files (x86)\TransMac
2013-10-13 11:02 - 2012-07-25 18:41 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-10-13 01:16 - 2013-10-13 01:16 - 00000000 ____D C:\Program Files (x86)\XeMu360
2013-10-12 20:24 - 2013-10-12 17:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-10-12 20:10 - 2013-10-12 20:10 - 00000000 ____D C:\FRST
2013-10-12 20:09 - 2013-10-12 20:09 - 00000168 _____ C:\Users\Wild-Pako\defogger_reenable
2013-10-12 17:16 - 2009-08-13 22:16 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Thunderbird
2013-10-12 17:08 - 2013-10-12 17:08 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\SCE
2013-10-12 17:07 - 2013-10-12 17:07 - 00000810 _____ C:\Users\Wild-Pako\Desktop\PlanetSide 2 PSG.lnk
2013-10-12 17:07 - 2013-10-12 17:07 - 00000810 _____ C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlanetSide 2 PSG.lnk
2013-10-11 19:53 - 2013-09-29 14:07 - 00000000 ____D C:\Windows\Minidump
2013-10-10 19:08 - 2013-10-02 21:06 - 00000000 ____D C:\Users\Wild-Pako\Documents\Criterion Games
2013-10-10 19:02 - 2013-10-10 19:02 - 00001084 _____ C:\Users\Public\Desktop\Need for Speed Most Wanted.lnk
2013-10-10 18:48 - 2013-09-25 19:40 - 00004112 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-10 18:48 - 2013-09-25 19:40 - 00003860 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-10 18:45 - 2009-08-13 17:20 - 00000000 ___RD C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-09 21:54 - 2013-10-09 21:53 - 00000000 ____D C:\Users\Wild-Pako\Documents\NFSTR
2013-10-09 18:38 - 2012-07-31 20:20 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-09 18:38 - 2012-07-31 20:20 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-09 18:38 - 2012-07-31 20:20 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-09 18:31 - 2009-07-14 06:45 - 00295824 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-09 18:26 - 2013-09-28 18:04 - 01593956 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-10-09 18:23 - 2013-09-25 19:07 - 00000000 ____D C:\Windows\system32\MRT
2013-10-09 18:22 - 2010-10-02 14:30 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-08 21:32 - 2013-10-08 21:32 - 00001374 _____ C:\Users\Wild-Pako\Desktop\farcry3.lnk
2013-10-08 21:32 - 2013-10-08 21:32 - 00000000 ____D C:\Users\Wild-Pako\Documents\My Games
2013-10-08 21:32 - 2013-10-08 21:32 - 00000000 ____D C:\ProgramData\Orbit
2013-10-08 21:20 - 2012-11-04 16:24 - 00328221 _____ C:\Windows\DirectX.log
2013-10-08 20:39 - 2013-10-08 20:39 - 00001513 _____ C:\Users\Wild-Pako\Desktop\Need For Speed The Run.lnk
2013-10-08 19:58 - 2013-10-08 19:58 - 00001922 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-10-08 19:58 - 2009-08-13 20:26 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-10-08 19:56 - 2013-10-08 19:56 - 00000000 ____D C:\Program Files\AVAST Software
2013-10-08 19:56 - 2013-10-08 19:52 - 00000000 ____D C:\ProgramData\AVAST Software
2013-10-08 19:08 - 2013-10-08 19:08 - 00000000 ____D C:\ProgramData\Futuremark
2013-10-08 19:07 - 2013-10-08 19:07 - 00000924 _____ C:\Users\Public\Desktop\3DMark Vantage.lnk
2013-10-08 19:06 - 2013-10-08 19:06 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-10-08 19:06 - 2013-10-08 19:06 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-10-08 00:48 - 2013-09-25 19:40 - 00002143 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-10-07 22:10 - 2013-10-01 12:42 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\CrossLoop
2013-10-07 21:59 - 2013-10-07 21:38 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-10-07 21:57 - 2013-10-07 21:57 - 00007601 _____ C:\Users\Wild-Pako\AppData\Local\Resmon.ResmonCfg
2013-10-07 21:39 - 2013-10-07 21:38 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-10-07 21:38 - 2013-10-07 21:38 - 00001343 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-10-07 21:38 - 2013-10-07 21:38 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-10-07 19:10 - 2013-10-07 19:10 - 00000000 ____D C:\ProgramData\ATI
2013-10-07 18:58 - 2013-10-07 18:58 - 00055617 _____ C:\Windows\SysWOW64\CCCInstall_201310071858030463.log
2013-10-07 18:58 - 2013-10-07 18:58 - 00000000 ____D C:\ProgramData\AMD
2013-10-07 18:58 - 2013-10-07 18:58 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2013-10-07 18:57 - 2013-09-18 19:38 - 00000000 ____D C:\Program Files\ATI Technologies
2013-10-07 18:56 - 2013-10-07 18:56 - 00018620 _____ C:\Windows\SysWOW64\CCCInstall_201310071856358562.log
2013-10-07 18:55 - 2013-10-07 18:55 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2013-10-07 18:53 - 2013-10-07 18:52 - 00000000 ____D C:\ProgramData\Package Cache
2013-10-06 23:20 - 2013-10-06 23:20 - 00000045 _____ C:\Users\Wild-Pako\Desktop\Neues Textdokument.txt
2013-10-05 17:01 - 2009-08-14 12:09 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\vlc
2013-10-04 22:11 - 2013-09-25 19:39 - 00001702 _____ C:\Users\Wild-Pako\Desktop\MPC-HC x64.lnk
2013-10-04 22:11 - 2013-09-25 19:39 - 00000000 ____D C:\Program Files\MPC-HC
2013-10-03 18:26 - 2013-10-03 18:20 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
2013-10-03 14:47 - 2013-10-03 13:51 - 00037130 _____ C:\pingstat.txt
2013-10-03 13:50 - 2013-10-03 13:49 - 00000332 _____ C:\Users\Wild-Pako\Desktop\Neues Textdokument.bat
2013-10-03 10:26 - 2013-10-03 10:26 - 00001160 _____ C:\Users\Wild-Pako\Desktop\launcher - Verknüpfung.lnk
2013-10-03 10:25 - 2013-09-29 11:35 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhoenixRC
2013-10-03 10:23 - 2013-09-29 11:39 - 00000000 ____D C:\Users\Wild-Pako\Documents\PhoenixRC
2013-10-03 04:52 - 2013-09-26 20:17 - 00001050 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk
2013-10-02 23:03 - 2013-10-02 23:03 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Sinvise Systems
2013-10-02 23:03 - 2013-10-02 23:03 - 00000000 ____D C:\Program Files (x86)\Sinvise Systems
2013-10-02 21:27 - 2013-10-02 21:26 - 00000000 ____D C:\Users\Wild-Pako\Documents\NFS Undercover
2013-10-02 21:24 - 2013-10-02 21:24 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Leadertech
2013-10-02 21:06 - 2013-10-02 21:06 - 00000000 ____D C:\ProgramData\Electronic Arts
2013-10-02 21:06 - 2013-10-02 21:06 - 00000000 ____D C:\ProgramData\EA Core
2013-10-02 19:29 - 2009-08-14 12:09 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\dvdcss
2013-09-29 13:48 - 2013-09-29 13:45 - 00000000 ____D C:\Users\Wild-Pako\Desktop\Prime95
2013-09-29 13:43 - 2013-09-29 13:43 - 00000948 _____ C:\Users\Wild-Pako\Desktop\Core Temp.lnk
2013-09-29 12:29 - 2012-11-07 23:30 - 00000647 _____ C:\Users\Public\Desktop\HELI-X4.lnk
2013-09-29 11:43 - 2013-09-29 11:43 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-09-28 22:33 - 2013-09-28 22:33 - 00004316 _____ C:\Windows\System32\Tasks\Feven 1.5-updater
2013-09-28 22:33 - 2013-09-28 22:33 - 00004220 _____ C:\Windows\System32\Tasks\Feven 1.5-codedownloader
2013-09-28 22:33 - 2013-09-28 22:33 - 00004120 _____ C:\Windows\System32\Tasks\Feven 1.5-enabler
2013-09-28 22:33 - 2013-09-28 22:31 - 00000000 ____D C:\Program Files (x86)\Feven 1.5
2013-09-28 22:32 - 2013-09-28 22:32 - 00000869 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2013-09-28 22:32 - 2013-09-28 22:32 - 00000000 ____D C:\Program Files\CPUID
2013-09-28 22:12 - 2013-09-28 22:12 - 00000000 ____D C:\Program Files\Defraggler
2013-09-28 22:11 - 2013-09-28 22:11 - 03084304 _____ (Piriform Ltd) C:\Users\Wild-Pako\Downloads\dfsetup215742_slim.exe
2013-09-28 22:11 - 2013-09-28 22:11 - 03084304 _____ (Piriform Ltd) C:\Users\Wild-Pako\Downloads\dfsetup215742_slim (1).exe
2013-09-28 22:07 - 2013-09-28 22:07 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\avgchrome
2013-09-28 22:03 - 2010-04-09 20:01 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-09-28 22:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Help
2013-09-28 21:41 - 2013-09-28 21:41 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\2K Games
2013-09-28 21:39 - 2013-09-28 21:39 - 00000902 _____ C:\Users\Wild-Pako\Desktop\SteamLess Mafia II.lnk
2013-09-28 21:39 - 2013-09-28 21:39 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steamless Mafia II Pack
2013-09-28 20:02 - 2010-08-07 22:58 - 00043520 _____ C:\Windows\SysWOW64\CmdLineExt03.dll
2013-09-28 13:59 - 2012-11-10 19:12 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\FileZilla
2013-09-28 13:51 - 2013-09-28 13:51 - 00001964 _____ C:\Users\Public\Desktop\FileZilla Client.lnk
2013-09-28 13:51 - 2013-09-28 13:51 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2013-09-27 23:09 - 2013-09-27 23:09 - 00000000 ____D C:\Users\Wild-Pako\Documents\Rockstar Games
2013-09-27 23:05 - 2013-09-27 23:05 - 00000000 __SHD C:\ProgramData\SecuROM
2013-09-27 23:05 - 2013-09-27 23:05 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Rockstar Games
2013-09-27 23:05 - 2013-09-27 17:13 - 00000044 _____ C:\DebugTraceAP.log
2013-09-27 22:54 - 2013-09-27 22:54 - 00000000 ____D C:\Windows\SysWOW64\xlive
2013-09-27 22:54 - 2013-09-27 22:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2013-09-27 22:54 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-09-27 22:51 - 2013-09-27 22:51 - 00001045 _____ C:\Users\Public\Desktop\Grand Theft Auto IV Complete Edition.lnk
2013-09-27 17:18 - 2013-09-27 17:14 - 00000000 ____D C:\tempvideo
2013-09-27 12:45 - 2013-09-27 12:43 - 00000000 ____D C:\Program Files (x86)\DU Meter
2013-09-27 12:43 - 2013-09-27 12:43 - 00000000 ____D C:\ProgramData\Hagel Technologies
2013-09-27 12:23 - 2013-09-27 12:23 - 00001047 _____ C:\Users\Wild-Pako\Desktop\Dropbox.lnk
2013-09-27 12:21 - 2013-09-27 12:21 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-09-27 11:48 - 2013-09-27 11:48 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Miranda IM
2013-09-27 11:48 - 2009-08-13 18:07 - 00000990 _____ C:\Users\Wild-Pako\Desktop\Miranda IM.lnk
2013-09-27 11:48 - 2009-08-13 18:07 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Miranda
2013-09-27 11:48 - 2009-08-13 18:07 - 00000000 ____D C:\Program Files (x86)\Miranda IM
2013-09-27 09:04 - 2009-08-13 22:16 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Thunderbird
2013-09-27 09:04 - 2009-08-13 18:06 - 00002050 _____ C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2013-09-27 08:51 - 2009-08-13 17:52 - 00064024 _____ C:\Users\Wild-Pako\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-27 08:22 - 2013-09-27 08:22 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\OpenOffice
2013-09-27 08:19 - 2013-09-27 08:19 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk
2013-09-27 08:19 - 2013-09-27 08:18 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-09-27 08:14 - 2009-08-13 17:58 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3
2013-09-27 08:11 - 2013-09-22 18:16 - 00000000 ____D C:\Windows\system32\appmgmt
2013-09-26 20:17 - 2013-09-26 20:17 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2013-09-26 15:00 - 2013-09-26 15:00 - 00000000 ____D C:\Windows\SysWOW64\searchplugins
2013-09-26 15:00 - 2013-09-26 15:00 - 00000000 ____D C:\Windows\SysWOW64\Extensions
2013-09-26 07:52 - 2013-09-26 07:52 - 00000000 _____ C:\Windows\setuperr.log
2013-09-25 22:15 - 2013-09-25 22:15 - 00000783 _____ C:\Users\Wild-Pako\Desktop\! - - Transfer - - !.lnk
2013-09-25 21:57 - 2013-09-25 21:57 - 00000000 ____D C:\ProgramData\Canneverbe Limited
2013-09-25 21:56 - 2013-09-25 21:56 - 00001913 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk
2013-09-25 21:56 - 2013-09-25 21:56 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Canneverbe Limited
2013-09-25 21:56 - 2013-09-25 21:56 - 00000000 ____D C:\Program Files (x86)\CDBurnerXP
2013-09-25 21:51 - 2013-09-25 21:51 - 00001501 _____ C:\Users\Wild-Pako\Desktop\Load.lnk
2013-09-25 21:34 - 2013-09-25 21:34 - 00001282 _____ C:\Users\Public\Desktop\EL3K My ELAS Remote Programmer.lnk
2013-09-25 21:34 - 2013-09-25 21:34 - 00000000 ____D C:\Program Files (x86)\Electronics Line
2013-09-25 20:41 - 2013-09-25 20:41 - 00002050 _____ C:\Users\Wild-Pako\Desktop\JDownloader.lnk
2013-09-25 20:41 - 2009-08-13 18:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-25 20:40 - 2013-09-25 20:40 - 00000000 ____D C:\Users\Wild-Pako\Programme
2013-09-25 20:31 - 2013-09-25 20:29 - 00000000 ____D C:\Windows\rescache
2013-09-25 19:59 - 2013-09-25 19:58 - 175636928 _____ C:\Users\Wild-Pako\Downloads\130254498000.rar.part
2013-09-25 19:59 - 2009-08-13 18:11 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Mozilla
2013-09-25 19:40 - 2013-09-25 19:39 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Google
2013-09-25 19:40 - 2013-09-25 19:39 - 00000000 ____D C:\Program Files (x86)\Google
2013-09-25 19:39 - 2013-09-25 19:39 - 00784872 _____ (Google Inc.) C:\Users\Wild-Pako\Downloads\ChromeSetup.exe
2013-09-25 19:38 - 2013-09-25 19:38 - 07990240 _____ (MPC-HC Team                                                 ) C:\Users\Wild-Pako\Downloads\MPC-HC.1.6.8.x64.exe
2013-09-25 19:38 - 2013-09-25 19:38 - 00001030 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-09-25 19:37 - 2013-09-25 19:37 - 23003252 _____ C:\Users\Wild-Pako\Downloads\vlc-2.0.8-win32.exe
2013-09-25 19:33 - 2009-08-13 17:20 - 00000000 ___RD C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-25 19:13 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-09-25 19:13 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-09-25 17:49 - 2009-07-14 09:46 - 00000000 ____D C:\Program Files\Windows Journal
2013-09-25 17:38 - 2013-09-25 17:38 - 00000000 ____D C:\ProgramData\Oracle
2013-09-25 17:36 - 2013-09-25 17:37 - 00868264 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-09-25 17:36 - 2013-09-25 17:37 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-09-25 17:36 - 2013-09-25 17:37 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-09-25 17:36 - 2013-09-25 17:37 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-09-25 17:36 - 2013-09-25 17:37 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-09-25 17:36 - 2010-10-02 14:28 - 00790440 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-09-25 17:36 - 2009-09-11 18:41 - 00000000 ____D C:\Program Files (x86)\Java
2013-09-25 17:28 - 2009-08-13 17:21 - 00001413 _____ C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\zh-HK
2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\tr-TR
2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-09-25 17:22 - 2013-09-24 19:14 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Winamp
2013-09-25 17:20 - 2013-09-25 17:20 - 02564703 _____ C:\Users\Wild-Pako\Downloads\CMI8738_WDM_0639XP.zip
2013-09-25 17:02 - 2013-09-25 16:55 - 00008799 _____ C:\Windows\IE10_main.log
2013-09-25 16:56 - 2013-09-25 16:56 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-09-25 16:56 - 2013-09-25 16:56 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-09-25 16:56 - 2013-09-25 16:56 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-09-25 16:56 - 2013-09-25 16:56 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-09-25 16:56 - 2013-09-25 16:56 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-09-25 16:56 - 2013-09-25 16:56 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-09-25 16:56 - 2013-09-25 16:56 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-09-25 16:56 - 2013-09-25 16:56 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-09-25 16:56 - 2013-09-25 16:56 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-09-25 16:56 - 2013-09-25 16:56 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-09-25 16:56 - 2013-09-25 16:56 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-09-25 16:39 - 2013-09-24 19:15 - 00000943 _____ C:\Users\Public\Desktop\Winamp.lnk
2013-09-25 16:39 - 2013-09-24 19:14 - 00000000 ____D C:\Program Files (x86)\Winamp
2013-09-25 16:38 - 2013-09-25 16:38 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in
2013-09-25 16:38 - 2013-09-25 16:38 - 00000000 ____D C:\Program Files (x86)\Winamp Detect
2013-09-25 16:37 - 2013-09-25 16:37 - 13385888 _____ (Nullsoft, Inc.) C:\Users\Wild-Pako\Downloads\winamp565_full_emusic-7plus_de-de.exe
2013-09-25 15:36 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-25 15:33 - 2009-08-13 18:04 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Adobe
2013-09-25 15:28 - 2009-08-13 18:06 - 00001111 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-09-23 01:28 - 2013-10-09 18:24 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-23 01:28 - 2013-10-09 18:24 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-23 01:27 - 2013-10-09 18:24 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-23 00:55 - 2013-10-09 18:24 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-23 00:55 - 2013-10-09 18:24 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-23 00:55 - 2013-10-09 18:24 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-23 00:54 - 2013-10-09 18:24 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-23 00:54 - 2013-10-09 18:24 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-22 18:27 - 2009-09-18 16:00 - 00000000 ____D C:\Program Files (x86)\Zylom Games
2013-09-22 18:25 - 2009-08-13 21:00 - 00000000 ____D C:\Program Files (x86)\Vuze
2013-09-22 18:25 - 2009-08-13 18:11 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Mozilla
2013-09-22 18:24 - 2009-08-13 17:46 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\TerraTec
2013-09-22 18:21 - 2013-04-02 19:18 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-09-22 18:21 - 2009-08-13 18:02 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Apple Computer
2013-09-22 18:21 - 2009-08-13 18:00 - 00000000 ____D C:\ProgramData\Apple Computer
2013-09-22 18:16 - 2012-07-25 19:08 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\ArcSoft
2013-09-22 18:11 - 2013-09-22 18:11 - 00003196 _____ C:\Windows\System32\Tasks\{758CECE7-FCF0-43F8-9FAD-6E45BC86DE8D}
2013-09-22 17:53 - 2010-07-08 16:48 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-09-21 17:09 - 2009-10-07 17:59 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\HCM Updater
2013-09-21 05:38 - 2013-10-09 18:24 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-21 05:30 - 2013-10-09 18:24 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-21 04:48 - 2013-10-09 18:24 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-21 04:39 - 2013-10-09 18:24 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-20 19:54 - 2013-09-20 19:49 - 00466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2013-09-20 19:54 - 2013-09-20 19:49 - 00444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2013-09-20 19:54 - 2013-09-20 19:49 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2013-09-20 19:54 - 2013-09-20 19:49 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2013-09-20 19:54 - 2013-09-20 19:49 - 00000628 _____ C:\Users\Public\Desktop\3DMark06.lnk
2013-09-20 19:49 - 2013-09-20 19:49 - 00000000 ____D C:\Program Files (x86)\OpenAL
2013-09-20 19:47 - 2013-09-20 19:47 - 00000000 ____D C:\Program Files (x86)\Futuremark
2013-09-20 19:44 - 2013-09-20 19:44 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\ATI
2013-09-20 19:44 - 2013-09-20 19:44 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\ATI
2013-09-20 19:43 - 2013-09-20 19:43 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2013-09-18 19:40 - 2013-09-18 19:40 - 00000000 _____ C:\Windows\ativpsrm.bin
2013-09-18 19:39 - 2013-09-18 19:39 - 00000000 ____D C:\Program Files (x86)\AMD APP
2013-09-18 19:38 - 2013-09-18 19:38 - 00000000 ____D C:\Program Files\ATI

Files to move or delete:
====================
C:\Users\Wild-Pako\FLASHSPI.EXE


Some content of TEMP:
====================
C:\Users\Wild-Pako\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-10-11 17:44

==================== End Of Log ============================
         

Alt 15.10.2013, 10:07   #12
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome - Standard

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 15.10.2013, 22:46   #13
Wild-Pako
 
Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome - Standard

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome



Hi,

vielen Dank soweit erstmal! Sieht schonmal gut aus, die meiste Werbung ist weg.

Hier nochmal das Log von dem Online Scanner

Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=34772e53e3191d488a35bb11f66580d2
# engine=15494
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-10-15 05:06:25
# local_time=2013-10-15 07:06:25 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=774 16777213 85 91 601701 158566657 0 0
# compatibility_mode=5893 16776573 100 94 38953 133486635 0 0
# scanned=96116
# found=1
# cleaned=0
# scan_time=2509
sh=9445111288F9D7822DB7E8748E0F1A1BA72A6221 ft=1 fh=1cf8df54d51c6459 vn="MSIL/Hoax.Agent.NAE application" ac=I fn="C:\Program Files (x86)\XeMu360\XeMu360.exe"
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=34772e53e3191d488a35bb11f66580d2
# engine=15494
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-10-15 08:37:47
# local_time=2013-10-15 10:37:47 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=774 16777213 85 91 614383 158579339 0 0
# compatibility_mode=5893 16776573 100 94 51635 133499317 0 0
# scanned=200721
# found=0
# cleaned=0
# scan_time=12112
         
Der Security Check bricht direkt ab mit der Meldung "Unsupported OS"

Sind noch weitere Aktionen notwendig ?

Gruß,
Michael

Alt 16.10.2013, 11:45   #14
schrauber
/// the machine
/// TB-Ausbilder
 

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome - Standard

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome



Fertig

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 16.10.2013, 19:56   #15
Wild-Pako
 
Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome - Standard

Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome



Hi,

so alles erledigt! Vielen vielen Dank für deine Super Hilfe! Ich hoffe nicht das ich sobald wieder Hilfe brauchen werde, aber wenn doch darf ich mich ja wieder melden oder ?

Viel Grüße,
Michael

Antwort

Themen zu Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome
adblock, andere, bedingt, chrome, dateien, firefox, google, installiert, massenhaft, plugins, popups, pup.optional.bundleinstaller.a, pup.optional.startpage.a, schonmal, umleitung, webseite, webseiten, windows, windows 7



Ähnliche Themen: Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome


  1. Firefox + Chrome stürzen ab bei div.Google-Diensten
    Log-Analyse und Auswertung - 03.08.2015 (17)
  2. Google Chrome - öffnet eine andere Seite beim Starten von Google Chrome (Win7)
    Plagegeister aller Art und deren Bekämpfung - 19.01.2015 (29)
  3. Windows 8.1: Werbe-Popups in Google Chrome und Opera
    Log-Analyse und Auswertung - 24.07.2014 (16)
  4. Windows 8.1 64 Bit; unerwünschte Popups im Chrome Browser
    Log-Analyse und Auswertung - 29.06.2014 (32)
  5. Nach der Installation von Windows 7 öffnen sich immer öfters popups erst in chrome nun auch in firefox
    Plagegeister aller Art und deren Bekämpfung - 04.06.2014 (19)
  6. Win 7: Google Chrome/Mozilla firefox lässt vermehrt Werbung auf Webseiten zu & Google Suchergebnisse scheinen manipuliert zu sein
    Log-Analyse und Auswertung - 29.04.2014 (8)
  7. [Google Chrome] Ständige Popups (Spyware, FreeScan) und Verlinkungen in allen Textpassagen
    Plagegeister aller Art und deren Bekämpfung - 08.04.2014 (12)
  8. Windows 7: Verlinkungen und Popups in Chrome
    Log-Analyse und Auswertung - 26.03.2014 (6)
  9. Ständige Popups in Chrome sowie Firefox, langsames Internet, Avast findet keine Fehler
    Log-Analyse und Auswertung - 24.03.2014 (21)
  10. Ständiges Öffnen von PopUps bei Firefox und Chrome
    Log-Analyse und Auswertung - 05.03.2014 (7)
  11. Windows 7: Werbung und Popups im Firefox, unterstrichene Wörter mit PopUps bei Mouse-Over EXP/JAVA.Rafold.A.Gen
    Log-Analyse und Auswertung - 03.02.2014 (5)
  12. Doppelunterstreichungen bei Firefox und Google Chrome
    Log-Analyse und Auswertung - 15.12.2013 (7)
  13. Windows 7 x64 - Werbung über dem gesamten Browserfenster bei Google Chrome/Firefox
    Log-Analyse und Auswertung - 21.09.2013 (5)
  14. delta-search Startseite in Google Chrome und Firefox
    Log-Analyse und Auswertung - 26.02.2013 (4)
  15. Google öffnet neue Tabs und Popups in Firefox
    Plagegeister aller Art und deren Bekämpfung - 24.10.2011 (3)
  16. Windows-Explorer, sowie Firefox sehr langsam!
    Log-Analyse und Auswertung - 07.08.2011 (5)
  17. Firefox öffnet Werbefenster (Pop Ups) sowie falsche Seiten beim Suchen mit GOOGLE
    Log-Analyse und Auswertung - 06.04.2009 (28)

Zum Thema Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome - Hallo Leute, seit gerauemer Zeit habe ich auf jeder Webseite Flash Werbung und Popups im überfluss. Die üblichen Firefox Plugins wie Adblock sind installiert, bringen aber nur bedingt etwas. Es - Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome...
Archiv
Du betrachtest: Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.